Vulnerability Description
Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command execution, via a crafted payload to the HTTPS port, because lighttpd listens on all network interfaces (including the external Internet) by default. NOTE: this may overlap CVE-2017-9980.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Greenpacket | Dv-360 Firmware | 2.10.14-g1.0.6.1 |
| Greenpacket | Dv-360 | - |
Related Weaknesses (CWE)
References
- https://www.shellcode.it/article/greenpacket-wimax/ExploitThird Party Advisory
- https://www.shellcode.it/article/greenpacket-wimax/ExploitThird Party Advisory
FAQ
What is CVE-2018-14067?
CVE-2018-14067 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command execution, via a crafted payload to the HTTPS port, because lighttpd listens on all netw...
How severe is CVE-2018-14067?
CVE-2018-14067 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-14067?
Check the references section above for vendor advisories and patch information. Affected products include: Greenpacket Dv-360 Firmware, Greenpacket Dv-360.