CVE-2018-0625: OS Command Injection
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via formSysCmd parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0625?
CVE-2018-0625 is a vulnerability in Aterm WG1200HP firmware Ver1.0.31 and earlier that allows an attacker with administrator rights to execute arbitrary OS commands.
How severe is CVE-2018-0625?
CVE-2018-0625 has a severity rating of 7.2 (Critical).
How does CVE-2018-0625 affect the Aterm WG1200HP firmware?
CVE-2018-0625 affects Aterm WG1200HP firmware Ver1.0.31 and earlier by allowing an attacker with administrator rights to execute arbitrary OS commands via the formSysCmd parameter.
Is the Nec Aterm Wg1200hp firmware vulnerable to CVE-2018-0625?
The Nec Aterm Wg1200hp firmware is vulnerable to CVE-2018-0625 if it is running Ver1.0.31 or earlier.
How can I fix CVE-2018-0625?
To fix CVE-2018-0625, it is recommended to update the Aterm WG1200HP firmware to a version later than Ver1.0.31.