CVE-2018-11094: Critical severity intelbras ncloud 300 firmware vulnerability
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the username, password, and other details are retrieved.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11094?
CVE-2018-11094 is a vulnerability found in Intelbras NCLOUD 300 1.0 devices that allows unauthorized access to certain endpoints.
How severe is CVE-2018-11094?
CVE-2018-11094 has a severity rating of 9.8 (Critical).
Which software version is affected by CVE-2018-11094?
CVE-2018-11094 affects Intelbras NCLOUD 300 1.0 firmware.
Are all Intelbras NCLOUD 300 devices vulnerable to CVE-2018-11094?
No, only the Intelbras NCLOUD 300 1.0 devices with specific firmware versions are vulnerable to CVE-2018-11094.
Is there a fix for CVE-2018-11094?
Unfortunately, there is no known fix or patch available for CVE-2018-11094 at this time. It is recommended to implement other security measures to mitigate the vulnerability.