CVE-2018-0665
Summary
| CVE | CVE-2018-0665 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-09 23:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed arbitrary scripts to the configuration data through a certain form field of the configuration page, which may be executed on another administrative user's web browser. This is a different vulnerability from CVE-2018-0666. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Yamaha | Nvr500 | - | All | All | All |
| Hardware | Yamaha | Nvr500 | - | All | All | All |
| Operating System | Yamaha | Nvr500 Firmware | All | All | All | All |
| Hardware | Yamaha | Rt57i | - | All | All | All |
| Hardware | Yamaha | Rt57i | - | All | All | All |
| Operating System | Yamaha | Rt57i Firmware | All | All | All | All |
| Hardware | Yamaha | Rt58i | - | All | All | All |
| Hardware | Yamaha | Rt58i | - | All | All | All |
| Operating System | Yamaha | Rt58i Firmware | All | All | All | All |
| Hardware | Yamaha | Rtx810 | - | All | All | All |
| Hardware | Yamaha | Rtx810 | - | All | All | All |
| Operating System | Yamaha | Rtx810 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| web116.jp/ced/support/news/contents/2018/20180829b.html | MISC | web116.jp | Third Party Advisory |
| JVN#69967692: Multiple script injection vulnerabilities in multiple Yamaha network devices | JVN | jvn.jp | Third Party Advisory |
| www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVN69967692.html | MISC | www.rtpro.yamaha.co.jp | Third Party Advisory |
| 【NTT西日本】Biz Boxルータ「N58i」、「N500」、「NVR500」、「RTX810」をご利用のお客さまへ - 法人・企業向けICTサービス | MISC | flets-w.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.