CVE-2018-0640: Buffer Overflow
Published Jan 9, 2019
·Updated
Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date parameter, time parameter, and offset parameter.
Affected Software
2 affected components
NEC Aterm Hc100rc Firmware<=1.0.1
NEC Aterm Hc100rc
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0640?
CVE-2018-0640 has been rated as high severity due to the potential for remote code execution.
2
How do I fix CVE-2018-0640?
To mitigate CVE-2018-0640, upgrade the Aterm HC100RC firmware to version 1.0.2 or later.
3
What vulnerabilities are associated with CVE-2018-0640?
CVE-2018-0640 involves a buffer overflow allowing attackers with administrator rights to execute arbitrary code.
4
Who is affected by CVE-2018-0640?
CVE-2018-0640 affects Aterm HC100RC devices running firmware version 1.0.1 or earlier.
5
Is CVE-2018-0640 exploitable over the internet?
Yes, CVE-2018-0640 can be exploited remotely if an attacker has network access to the vulnerable device.