First published: Wed May 02 2018(Updated: )
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Watchguard Ap200 Firmware | <1.2.9.15 | |
Watchguard Ap200 | ||
Watchguard Ap102 Firmware | <1.2.9.15 | |
Watchguard Ap102 | ||
Watchguard Ap100 Firmware | <1.2.9.15 | |
WatchGuard AP100 | ||
Watchguard Ap300 Firmware | <2.0.0.10 | |
Watchguard Ap300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-10577.
The severity level of CVE-2018-10577 is critical with a score of 8.8.
WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10 are affected.
The vulnerability allows authenticated users to upload files containing code to the web root, potentially leading to remote code execution.
To fix CVE-2018-10577, update the firmware of the affected WatchGuard devices to version 1.2.9.15 for AP100, AP102, and AP200, and version 2.0.0.10 for AP300.