Vulnerability Description
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL (Attackers can login using the "admin" username with password "admin" after a successful attack).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wi2Be | Smart Hp Wmt | r1.2.20_201400922 |
Related Weaknesses (CWE)
References
- https://vulncode.com/advisory/CVE-2018-14078Third Party Advisory
- https://vulncode.com/advisory/CVE-2018-14078Third Party Advisory
FAQ
What is CVE-2018-14078?
CVE-2018-14078 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL (Attackers can login using the "admin" username wit...
How severe is CVE-2018-14078?
CVE-2018-14078 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-14078?
Check the references section above for vendor advisories and patch information. Affected products include: Wi2Be Smart Hp Wmt.