MEDIUM · 6.1

CVE-2018-14784

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable to several cross-site scripting attacks, allowing a remote attacker to run arbit...

Vulnerability Description

NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable to several cross-site scripting attacks, allowing a remote attacker to run arbitrary code on the device.

CVSS Score

6.1

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
NetcommwirelessNwl-25 Firmware<= 2.0.29.11
NetcommwirelessNwl-25-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-14784?

CVE-2018-14784 is a vulnerability with a CVSS score of 6.1 (MEDIUM). NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable to several cross-site scripting attacks, allowing a remote attacker to run arbit...

How severe is CVE-2018-14784?

CVE-2018-14784 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-14784?

Check the references section above for vendor advisories and patch information. Affected products include: Netcommwireless Nwl-25 Firmware, Netcommwireless Nwl-25.