Vulnerability Description
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cerio | Dt-300N Firmware | >= 1.1.6, <= 1.1.12 |
| Cerio | Dt-300N | - |
Related Weaknesses (CWE)
References
- https://www.fortiguard.com/zeroday/FG-VD-18-149Third Party Advisory
- https://www.fortiguard.com/zeroday/FG-VD-18-149Third Party Advisory
FAQ
What is CVE-2018-18852?
CVE-2018-18852 is a vulnerability with a CVSS score of 8.8 (HIGH). Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited i...
How severe is CVE-2018-18852?
CVE-2018-18852 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-18852?
Check the references section above for vendor advisories and patch information. Affected products include: Cerio Dt-300N Firmware, Cerio Dt-300N.