First published: Wed Jan 09 2019(Updated: )
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter of a certain URL, different URL from CVE-2018-0634.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Nec Aterm Hc100rc Firmware | <=1.0.1 | |
Nec Aterm Hc100rc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0636 is considered a high severity vulnerability due to the potential for arbitrary command execution.
To fix CVE-2018-0636, update Aterm HC100RC firmware to version 1.0.2 or later.
CVE-2018-0636 is caused by improper handling of the FactoryPassword parameter which allows command injection for attackers with administrator rights.
Users of Aterm HC100RC devices running firmware version 1.0.1 or earlier are affected by CVE-2018-0636.
Yes, restricting access to the device's administrative controls can serve as a temporary workaround for CVE-2018-0636.