SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-11240

If the command syntax is correct, there is code execution both on the other modem and on the main servers.

CRITICAL 9.8EPSS 2.29%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' feature of the T-Router protocol. If the command syntax is correct, there is code execution both on the other modem and on the main servers. This is fixed in production builds as of Spring 2018.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.29% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-732
Affected
softcase/t-router firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.