// For flags

CVE-2018-20512

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.

Los dispositivos EPON CPE-WiFi 2.0.4-X000 son vulnerables a un escalado de privilegios enviando cookies de cooLogin=1, cooUser=admin y timestamp=-1.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-12-27 CVE Reserved
  • 2019-01-03 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-565: Reliance on Cookies without Validation and Integrity Checking
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd108bn
Search vendor "Cdatatec" for product "Fd108bn"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd111hz
Search vendor "Cdatatec" for product "Fd111hz"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd111y
Search vendor "Cdatatec" for product "Fd111y"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd114y
Search vendor "Cdatatec" for product "Fd114y"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd212gw
Search vendor "Cdatatec" for product "Fd212gw"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd212h
Search vendor "Cdatatec" for product "Fd212h"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd214gh
Search vendor "Cdatatec" for product "Fd214gh"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd214gw
Search vendor "Cdatatec" for product "Fd214gw"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd404gh
Search vendor "Cdatatec" for product "Fd404gh"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd404gw
Search vendor "Cdatatec" for product "Fd404gw"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd600-104
Search vendor "Cdatatec" for product "Fd600-104"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd600-104g
Search vendor "Cdatatec" for product "Fd600-104g"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd600-108f-hz500
Search vendor "Cdatatec" for product "Fd600-108f-hz500"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd600-111g
Search vendor "Cdatatec" for product "Fd600-111g"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd600-111gw
Search vendor "Cdatatec" for product "Fd600-111gw"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd600-301
Search vendor "Cdatatec" for product "Fd600-301"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd600-301gw
Search vendor "Cdatatec" for product "Fd600-301gw"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd600-304
Search vendor "Cdatatec" for product "Fd600-304"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd600-304ga-hr500
Search vendor "Cdatatec" for product "Fd600-304ga-hr500"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd600-304ga-hr511
Search vendor "Cdatatec" for product "Fd600-304ga-hr511"
--
Safe
Cdatatec
Search vendor "Cdatatec"
Epon Cpe-wifi Devices Firmware
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware"
2.0.4-x000
Search vendor "Cdatatec" for product "Epon Cpe-wifi Devices Firmware" and version "2.0.4-x000"
-
Affected
in Cdatatec
Search vendor "Cdatatec"
Fd600-521g
Search vendor "Cdatatec" for product "Fd600-521g"
--
Safe