CVE-2018-18852
57Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 64%
from disclosure to weapon0 days
Published on NVDJun 18
1st PoCJan 26
VulnCheckJun 18
exploitation probability
64%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.
Affected products
n/a · n/apublic PoCs found — 2
vulncheckvulncheck.com/xdb/2256efd99091unverifiedvulncheckvulncheck.com/xdb/7ed86bd802c3unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.