CVE-2018-12456
Last modified
CVE-2018-12456 is a vulnerability of currently unknown severity. Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions such as changing the wireless SSID, rebooting the device, editing access control lists, or activating remote access.. EPSS estimates a 0.89% chance of exploitation in the next 30 days.
Description
Intelbras NPLUG 1.0.0.14 wireless repeater devices have no CSRF token protection in the web interface, allowing attackers to perform actions such as changing the wireless SSID, rebooting the device, editing access control lists, or activating remote access.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intelbras | Nplug Firmware | 1.0.0.14 |
References
- http://seclists.org/fulldisclosure/2018/Oct/18Exploit, Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2018/Oct/18Exploit, Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12456?
How severe is CVE-2018-12456?
How do I fix CVE-2018-12456?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-12448Whale Browser before 1.3.48.4 displays no URL information bu…
- CVE-2018-12449The Whale browser installer 0.4.3.0 and earlier versions all…
- CVE-2018-1245RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 …9
- CVE-2018-12453Type confusion in the xgroupCommand function in t_stream.c i…
- CVE-2018-12454The _addguess function of a simplelottery smart contract imp…
- CVE-2018-12455Intelbras NPLUG 1.0.0.14 wireless repeater devices have a cr…
- CVE-2018-12457expressCart before 1.1.6 allows remote attackers to create a…
- CVE-2018-12458An improper integer type in the mpeg4_encode_gop_header func…6.5
- CVE-2018-12459An inconsistent bits-per-sample value in the ff_mpeg4_decode…
- CVE-2018-1246Dell EMC Unity and UnityVSA contains reflected cross-site sc…4.7
- CVE-2018-12460libavcodec in FFmpeg 4.0 may trigger a NULL pointer derefere…
- CVE-2018-12461Fixed issues with NetIQ eDirectory prior to 9.1.1 when check…3.5
Are you affected by CVE-2018-12456?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
