CVE-2018-11491 — Improper Authentication in Hg100 Firmware

Severity
9.8CRITICALNVD
EPSS
5.3%
top 9.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 25
Latest updateMay 14

Description

ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

â–¶NVDasus/hg100_firmware< 1.05.12

🔴Vulnerability Details

2
GHSA
GHSA-qgh2-wrrh-xwch: ASUS HG100 devices with firmware before 1↗2022-05-14
â–¶
CVEList
CVE-2018-11491: ASUS HG100 devices with firmware before 1↗2018-07-25
â–¶
CVE-2018-11491 — Improper Authentication in Asus | cvebase