CVE-2018-0635: OS Command Injection
Published Jan 9, 2019
·Updated
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via filename parameter.
Affected Software
2 affected components
NEC Aterm Hc100rc Firmware<=1.0.1
NEC Aterm Hc100rc
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0635?
CVE-2018-0635 is considered a high severity vulnerability due to its potential to allow an attacker with administrator rights to execute arbitrary OS commands.
2
How do I fix CVE-2018-0635?
To fix CVE-2018-0635, upgrade the Aterm HC100RC firmware to a version later than 1.0.1.
3
Who is affected by CVE-2018-0635?
Users of Aterm HC100RC devices running firmware version 1.0.1 or earlier are affected by CVE-2018-0635.
4
What types of attacks can exploit CVE-2018-0635?
CVE-2018-0635 can be exploited to execute arbitrary OS commands, leading to potential system compromise.
5
What are the implications of CVE-2018-0635?
The implications of CVE-2018-0635 include unauthorized access and control over the affected Aterm HC100RC device.