Arbitrary OS Command Execution in Aterm Network Routers by NEC
CVE-2018-16195

8.8HIGH

Key Information:

Vendor
CVE Published:
9 January 2019

What is CVE-2018-16195?

The Aterm WF1200CR and Aterm WG1200CR routers from NEC are vulnerable to an issue that allows an attacker on the same network segment to execute arbitrary operating system commands. This is achieved through an exploit targeting the SOAP interface of the Universal Plug and Play (UPnP) protocol. Devices running Aterm WF1200CR firmware version 1.1.1 and earlier, as well as Aterm WG1200CR firmware version 1.0.1 and earlier, are at risk and should be updated to mitigate potential exploitation.

Affected Version(s)

Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier)

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.