CVE-2018-0629: OS Command Injection
Published Jan 9, 2019
·Updated
Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.
Affected Software
2 affected components
NEC Aterm W300P firmware<=1.0.13
NEC Aterm W300P
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-0629?
CVE-2018-0629 is a vulnerability that allows an attacker with administrator rights to execute arbitrary OS commands on Aterm W300P Ver1.0.13 and earlier.
2
What is the severity of CVE-2018-0629?
CVE-2018-0629 has a severity rating of 7.2, which is classified as critical.
3
How does CVE-2018-0629 work?
CVE-2018-0629 allows an attacker to execute arbitrary OS commands via HTTP request and response.
4
What software is affected by CVE-2018-0629?
Aterm W300P Ver1.0.13 and earlier versions are affected by CVE-2018-0629.
5
How can I fix CVE-2018-0629?
To fix CVE-2018-0629, it is recommended to update the firmware to a version higher than 1.0.13.