CVE-2018-0665: Medium severity yamaha rt57i firmware vulnerability
Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed arbitrary scripts to the configuration data through a certain form field of the configuration page, which may be executed on another administrative user's web browser. This is a different vulnerability from CVE-2018-0666.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0665?
The severity of CVE-2018-0665 is medium with a CVSS score of 6.8.
How can an administrative user embed arbitrary scripts to the configuration data in Yamaha routers affected by CVE-2018-0665?
An administrative user can embed arbitrary scripts to the configuration data through a certain form field of the configuration page.
Which Yamaha router models are affected by CVE-2018-0665?
Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier are affected by CVE-2018-0665.
What is the reference for more information about CVE-2018-0665?
For more information about CVE-2018-0665, you can refer to the following links: http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVN69967692.html, https://flets-w.com/solution/kiki_info/info/180829.html, https://jvn.jp/en/jp/JVN69967692/index.html.
How can I fix CVE-2018-0665 in Yamaha routers?
To fix CVE-2018-0665 in Yamaha routers, it is recommended to update the firmware to the latest version provided by Yamaha.