CVE-2018-18473
Summary
| CVE | CVE-2018-18473 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-21 16:00:00 UTC |
| Updated | 2019-09-09 22:15:00 UTC |
| Description | A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow attackers to enable an SSH daemon via the "kankichi" or "kamiyo4" password to the _secret1.htm URI. Subsequently, the default password of root for the root account allows an attacker to conduct remote code execution and as a result take over the system. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Patlite | Nbm-d88n | - | All | All | All |
| Hardware | Patlite | Nbm-d88n | - | All | All | All |
| Operating System | Patlite | Nbm-d88n Firmware | - | All | All | All |
| Operating System | Patlite | Nbm-d88n Firmware | - | All | All | All |
| Hardware | Patlite | Nhl-3fb1 | - | All | All | All |
| Hardware | Patlite | Nhl-3fb1 | - | All | All | All |
| Operating System | Patlite | Nhl-3fb1 Firmware | - | All | All | All |
| Operating System | Patlite | Nhl-3fb1 Firmware | - | All | All | All |
| Hardware | Patlite | Nhl-3fv1n | - | All | All | All |
| Hardware | Patlite | Nhl-3fv1n | - | All | All | All |
| Operating System | Patlite | Nhl-3fv1n Firmware | - | All | All | All |
| Operating System | Patlite | Nhl-3fv1n Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Information|PATLITE | CONFIRM | www.patlite.com | |
| herolab.usd.de/wp-content/uploads/sites/4/usd20180020.txt | MISC | herolab.usd.de | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.