CVE-2018-0512
UnknownEPSS 0.67%
Last modified
CVE-2018-0512 is a vulnerability of currently unknown severity. Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Iodata | Hdl-Xr Firmware | <= 2.01 |
| Iodata | Hdl-Xrw Firmware | <= 2.01 |
| Iodata | Hdl-Xr2u Firmware | <= 2.01 |
| Iodata | Hdl-Xr2uw Firmware | <= 2.01 |
| Iodata | Hdl-Xv Firmware | <= 1.50 |
| Iodata | Hdl-Xvw Firmware | <= 1.50 |
| Iodata | Hdl-Gt Firmware | <= 1.37 |
| Iodata | Hdl-Gtr Firmware | <= 1.37 |
| Iodata | Hdl-A Firmware | <= 1.26 |
| Iodata | Hdl-Ah Firmware | <= 1.26 |
| Iodata | Hdl2-A Firmware | <= 1.26 |
| Iodata | Hdl2-Ah Firmware | <= 1.26 |
| Iodata | Hdl-T Firmware | <= 1.12 |
| Iodata | Hls-C Firmware | <= 1.12 |
| Iodata | Hvl-A Firmware | <= 2.04 |
| Iodata | Hvl-At Firmware | <= 2.04 |
| Iodata | Hvl-Ata Firmware | <= 2.04 |
| Iodata | Hvl-S Firmware | <= 1.00 |
| Iodata | Hfas1 Firmware | <= 1.40 |
| Iodata | Whg-Napg Firmware | <= 1.08 |
| Iodata | Whg-Napga Firmware | <= 1.08 |
| Iodata | Whg-Napgal Firmware | <= 1.05 |
| Iodata | Whg-Ac1750a Firmware | <= 3.00 |
| Iodata | Whg-Ac1750 Firmware | <= 1.07 |
| Iodata | Whg-Ac1750al Firmware | <= 1.07 |
| Iodata | Wn-Ax1167gr Firmware | <= 3.11 |
| Iodata | Wn-Gx300gr Firmware | <= 2.00 |
| Iodata | Wnpr2600g Firmware | <= 1.01 |
| Iodata | Wnpr1750g Firmware | <= 1.01 |
| Iodata | Wnpr1167g Firmware | <= 1.00 |
| Iodata | Wnpr1167f Firmware | <= 1.00 |
| Iodata | Wn-Ag750dgr Firmware | <= 1.08 |
| Iodata | Wn-G300r Firmware | <= 1.14 |
| Iodata | Wn-G300r3 Firmware | <= 1.04 |
| Iodata | Wn-Ag300dgr Firmware | <= 1.05 |
| Iodata | Wn-Ac1600dgr Firmware | <= 2.06 |
| Iodata | Wn-Ac1167dgr Firmware | <= 1.02 |
| Iodata | Wn-G300ex Firmware | <= 1.01 |
| Iodata | Wn-Ac1300ex Firmware | <= 1.02 |
| Iodata | Wn-Ac583trk Firmware | <= 1.05 |
| Iodata | Wn-Ac583rk Firmware | <= 1.06 |
| Iodata | Wn-G300sr Firmware | <= 1.00 |
| Iodata | Bx-Vp1 Firmware | <= 2.01 |
| Iodata | Gv-Ntx1 Firmware | <= 1.02.00 |
| Iodata | Gv-Ntx2 Firmware | <= 1.02.00 |
References
- http://www.iodata.jp/support/information/2018/magicalfinder/Vendor Advisory
- https://jvn.jp/en/jp/JVN36048131/index.htmlThird Party Advisory, VDB Entry
- http://www.iodata.jp/support/information/2018/magicalfinder/Vendor Advisory
- https://jvn.jp/en/jp/JVN36048131/index.htmlThird Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-0512?
Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.
How severe is CVE-2018-0512?
Severity scoring for CVE-2018-0512 is pending analysis. The EPSS model estimates a 0.67% probability of exploitation in the next 30 days.
How do I fix CVE-2018-0512?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2018-0512?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
