CVE-2018-0636: OS Command Injection
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter of a certain URL, different URL from CVE-2018-0634.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0636?
CVE-2018-0636 is considered a high severity vulnerability due to the potential for arbitrary command execution.
How do I fix CVE-2018-0636?
To fix CVE-2018-0636, update Aterm HC100RC firmware to version 1.0.2 or later.
What causes CVE-2018-0636?
CVE-2018-0636 is caused by improper handling of the FactoryPassword parameter which allows command injection for attackers with administrator rights.
Who is affected by CVE-2018-0636?
Users of Aterm HC100RC devices running firmware version 1.0.1 or earlier are affected by CVE-2018-0636.
Is there a workaround for CVE-2018-0636?
Yes, restricting access to the device's administrative controls can serve as a temporary workaround for CVE-2018-0636.