CVE-2018-0626: OS Command Injection
Published Jan 9, 2019
·Updated
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd in formWsc parameter.
Affected Software
2 affected components
NEC Aterm WG1200HP firmware<=1.0.31
NEC Aterm WG1200HP
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-0626?
CVE-2018-0626 is a vulnerability in Aterm WG1200HP firmware Ver1.0.31 and earlier that allows an attacker with administrator rights to execute arbitrary OS commands.
2
How severe is CVE-2018-0626?
CVE-2018-0626 has a severity rating of 7.2, which is considered critical.
3
Which software is affected by CVE-2018-0626?
Aterm WG1200HP firmware Ver1.0.31 and earlier is affected by CVE-2018-0626.
4
How can an attacker exploit CVE-2018-0626?
An attacker with administrator rights can exploit CVE-2018-0626 by executing arbitrary OS commands via the 'sysCmd' parameter in the 'formWsc' parameter.
5
Is there a fix for CVE-2018-0626?
Yes, upgrading to a version later than Ver1.0.31 of the Aterm WG1200HP firmware fixes CVE-2018-0626.