CVE-2018-20512
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/01/2019
Last modified:
03/10/2019
Description
EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:cdatatec:epon_cpe-wifi_devices_firmware:2.0.4-x000:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd108bn:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd111hz:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd111y:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd114y:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd212gw:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd212h:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd214gh:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd214gw:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd404gh:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd404gw:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd600-104:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd600-104g:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd600-108f-hz500:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:cdatatec:fd600-111g:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page