CVE-2018-0666: Medium severity yamaha rt57i firmware vulnerability
Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed arbitrary scripts to the configuration data through a certain form field of the configuration page, which may be executed on another administrative user's web browser. This is a different vulnerability from CVE-2018-0665.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-0666.
Which Yamaha routers are affected by the vulnerability?
Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier are affected by the vulnerability.
What is the severity of CVE-2018-0666?
The severity of CVE-2018-0666 is medium (6.8).
How can an administrative user exploit the vulnerability?
An administrative user can embed arbitrary scripts to the configuration data through a certain form field of the configuration page.
Is there a fix available for CVE-2018-0666?
Yes, please refer to the references provided for details on the fix.