Vulnerability Description
An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware, running on Anker Roav A1 Dashcam version RoavA1SWV1.9. The HTTP server allows for arbitrary firmware binaries to be uploaded which will be flashed upon next reboot. An attacker can send an HTTP PUT request or upgrade firmware request to trigger this vulnerability.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Anker-In | Roav Dashcam A1 Firmware | 1.9 |
| Anker-In | Roav Dashcam A1 | - |
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0689ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0689ExploitThird Party Advisory
FAQ
What is CVE-2018-4018?
CVE-2018-4018 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware, running on Anker Roav A1 Dashcam version RoavA1SWV1.9. The HTTP server allows for arbitrary firmware binaries to be...
How severe is CVE-2018-4018?
CVE-2018-4018 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-4018?
Check the references section above for vendor advisories and patch information. Affected products include: Anker-In Roav Dashcam A1 Firmware, Anker-In Roav Dashcam A1.