CVE-2018-10577
Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as root.
Se ha descubierto un problema en los dispositivos WatchGuard AP100, AP102 y AP200 con firmware en versiones anteriores a la 1.2.9.15 y en los dispositivos AP300 con firmware en versiones anteriores a la 2.0.0.10. La funcionalidad de subida de archivos permite que cualquier usuario autenticado en la interfaz web suba archivos que contienen código al root web, lo que permite que estos archivos se ejecuten como root.
WatchGuard Access Points running firmware before version 1.2.9.15 suffer from hard-coded credential, hidden authentication, file upload, and incorrect validation vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-04-30 CVE Reserved
- 2018-05-02 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2018/May/12 | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/45409 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Watchguard Search vendor "Watchguard" | Ap200 Firmware Search vendor "Watchguard" for product "Ap200 Firmware" | < 1.2.9.15 Search vendor "Watchguard" for product "Ap200 Firmware" and version " < 1.2.9.15" | - |
Affected
| in | Watchguard Search vendor "Watchguard" | Ap200 Search vendor "Watchguard" for product "Ap200" | - | - |
Safe
|
Watchguard Search vendor "Watchguard" | Ap102 Firmware Search vendor "Watchguard" for product "Ap102 Firmware" | < 1.2.9.15 Search vendor "Watchguard" for product "Ap102 Firmware" and version " < 1.2.9.15" | - |
Affected
| in | Watchguard Search vendor "Watchguard" | Ap102 Search vendor "Watchguard" for product "Ap102" | - | - |
Safe
|
Watchguard Search vendor "Watchguard" | Ap100 Firmware Search vendor "Watchguard" for product "Ap100 Firmware" | < 1.2.9.15 Search vendor "Watchguard" for product "Ap100 Firmware" and version " < 1.2.9.15" | - |
Affected
| in | Watchguard Search vendor "Watchguard" | Ap100 Search vendor "Watchguard" for product "Ap100" | - | - |
Safe
|
Watchguard Search vendor "Watchguard" | Ap300 Firmware Search vendor "Watchguard" for product "Ap300 Firmware" | < 2.0.0.10 Search vendor "Watchguard" for product "Ap300 Firmware" and version " < 2.0.0.10" | - |
Affected
| in | Watchguard Search vendor "Watchguard" | Ap300 Search vendor "Watchguard" for product "Ap300" | - | - |
Safe
|