CVE-2018-0638: OS Command Injection
Published Jan 9, 2019
·Updated
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameter.
Affected Software
2 affected components
NEC Aterm Hc100rc Firmware<=1.0.1
NEC Aterm Hc100rc
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0638?
CVE-2018-0638 has been classified with a high severity due to its potential to allow arbitrary OS command execution.
2
How do I fix CVE-2018-0638?
To fix CVE-2018-0638, upgrade the Aterm HC100RC firmware to version 1.0.2 or later.
3
What are the potential impacts of CVE-2018-0638?
The impact of CVE-2018-0638 includes unauthorized access to the system and execution of malicious commands.
4
Who is affected by CVE-2018-0638?
CVE-2018-0638 affects users of the Aterm HC100RC firmware versions 1.0.1 and earlier.
5
How can an attacker exploit CVE-2018-0638?
An attacker can exploit CVE-2018-0638 by gaining administrative access and using the import.cgi encKey parameter to execute arbitrary commands.