CVE-2018-0630: OS Command Injection
Published Jan 9, 2019
·Updated
Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd parameter.
Affected Software
2 affected components
NEC Aterm W300P firmware<=1.0.13
NEC Aterm W300P
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0630?
The severity of CVE-2018-0630 is critical with a CVSS score of 7.2.
2
How does CVE-2018-0630 affect Aterm W300P Ver1.0.13 and earlier?
CVE-2018-0630 allows an attacker with administrator rights to execute arbitrary OS commands via the sysCmd parameter on Aterm W300P Ver1.0.13 and earlier.
3
What is the affected software for CVE-2018-0630?
The affected software for CVE-2018-0630 is Aterm W300P Ver1.0.13 and earlier.
4
How can an attacker exploit CVE-2018-0630?
An attacker with administrator rights can exploit CVE-2018-0630 by executing arbitrary OS commands through the sysCmd parameter.
5
Are there any known fixes for CVE-2018-0630?
It is recommended to update to a version later than Aterm W300P Ver1.0.13 to mitigate CVE-2018-0630.