VulnerabilityModified
CVE-2018-16194
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.
HIGH 7.2EPSS 1.40%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.
- CVSS 3.0
- 7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- nec/aterm wf1200cr firmware · nec/aterm wg1200cr firmware
- Source
- vultures@jpcert.or.jp
References
- https://jpn.nec.com/security-info/secinfo/nv18-021.htmlVendor Advisory
- https://jvn.jp/en/jp/JVN87535892/index.htmlThird Party Advisory
- https://jpn.nec.com/security-info/secinfo/nv18-021.htmlVendor Advisory
- https://jvn.jp/en/jp/JVN87535892/index.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.