CVE-2018-0627: OS Command Injection
Published Jan 9, 2019
·Updated
Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.
Affected Software
2 affected components
NEC Aterm WG1200HP firmware<=1.0.31
NEC Aterm WG1200HP
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-0627?
CVE-2018-0627 is a vulnerability in Aterm WG1200HP firmware Ver1.0.31 and earlier that allows an attacker with administrator rights to execute arbitrary OS commands.
2
How severe is CVE-2018-0627?
CVE-2018-0627 has a severity rating of 7.2 (Critical).
3
What software versions are affected by CVE-2018-0627?
Aterm WG1200HP firmware Ver1.0.31 and earlier is affected by CVE-2018-0627.
4
How can an attacker exploit CVE-2018-0627?
An attacker with administrator rights can exploit CVE-2018-0627 by executing arbitrary OS commands via the targetAPSsid parameter.
5
Is there a fix for CVE-2018-0627?
At the moment, there is no known fix for CVE-2018-0627. It is recommended to update to a newer version of the firmware if available.