CVE-2018-0634: OS Command Injection
Published Jan 9, 2019
·Updated
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter or bootmode parameter of a certain URL.
Affected Software
2 affected components
NEC Aterm Hc100rc Firmware<=1.0.1
NEC Aterm Hc100rc
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0634?
CVE-2018-0634 is classified as a critical vulnerability due to the ability for attackers to execute arbitrary OS commands with administrator rights.
2
How do I fix CVE-2018-0634?
To fix CVE-2018-0634, you should update the Aterm HC100RC firmware to a version later than 1.0.1.
3
What are the affected devices for CVE-2018-0634?
CVE-2018-0634 affects Aterm HC100RC devices running firmware version 1.0.1 and earlier.
4
Can CVE-2018-0634 be exploited remotely?
Yes, CVE-2018-0634 can potentially be exploited remotely by an attacker with administrator access.
5
What parameters are involved in CVE-2018-0634?
CVE-2018-0634 involves the FactoryPassword and bootmode parameters in a specific URL to execute arbitrary commands.