CVE-2018-10577: Malicious File Upload
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as root.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-10577.
What is the severity level of CVE-2018-10577?
The severity level of CVE-2018-10577 is critical with a score of 8.8.
Which devices are affected by CVE-2018-10577?
WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10 are affected.
What is the impact of CVE-2018-10577?
The vulnerability allows authenticated users to upload files containing code to the web root, potentially leading to remote code execution.
How can I fix CVE-2018-10577?
To fix CVE-2018-10577, update the firmware of the affected WatchGuard devices to version 1.2.9.15 for AP100, AP102, and AP200, and version 2.0.0.10 for AP300.