CVE-2018-5266
Last modified
CVE-2018-5266 is a vulnerability of currently unknown severity. Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading the loginName lines at the js/userLogin.js URI. NOTE: default passwords for the standard usernames are listed in the product's documentation: Dealer with password seatel3, SysAdmin with password seatel2, and User with password seatel1.. EPSS estimates a 2.02% chance of exploitation in the next 30 days.
Description
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading the loginName lines at the js/userLogin.js URI. NOTE: default passwords for the standard usernames are listed in the product's documentation: Dealer with password seatel3, SysAdmin with password seatel2, and User with password seatel1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cobham | Sea Tel 121 Firmware | 222701 |
References
- http://misteralfa-hack.blogspot.cl/2018/01/seatelcobham-terminales-satelitales.htmlExploit, Third Party Advisory
- http://misteralfa-hack.blogspot.cl/2018/01/seatelcobham-terminales-satelitales.htmlExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5266?
How severe is CVE-2018-5266?
How do I fix CVE-2018-5266?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5259Discuz! DiscuzX X3.4 allows remote authenticated users to by…
- CVE-2018-5261An issue was discovered in Flexense DiskBoss 8.8.16 and earl…
- CVE-2018-5262A stack-based buffer overflow in Flexense DiskBoss 8.8.16 an…
- CVE-2018-5263The StackIdeas EasyDiscuss (aka com_easydiscuss) extension b…
- CVE-2018-5264Ubiquiti UniFi 52 devices, when Hotspot mode is used, allow …
- CVE-2018-5265Ubiquiti EdgeOS 1.9.1 on EdgeRouter Lite devices allows remo…
- CVE-2018-5267Cobham Sea Tel 121 build 222701 devices allow remote attacke…
- CVE-2018-5268In OpenCV 3.3.1, a heap-based buffer overflow happens in cv:…5.5
- CVE-2018-5269In OpenCV 3.3.1, an assertion failure happens in cv::RBaseSt…5.5
- CVE-2018-5270In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.…7.8
- CVE-2018-5271In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.…
- CVE-2018-5272In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.…
Are you affected by CVE-2018-5266?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
