← back
CVE-2018-18852observed exploitation

CVE-2018-18852

57Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actepss 64%
from disclosure to weapon0 days
Published on NVDJun 18
1st PoCJan 26
VulnCheckJun 18
exploitation probability
64%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.