CVE-2018-10576 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 1.5% (pctl 73)
Patch early
A public exploit exists.
Description
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a local system account (instead of the dedicated web-only user).
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.47% — more likely to be exploited than 73% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-04-30 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| watchguard | ap100 |
| watchguard | ap100 firmware |
| watchguard | ap102 |
| watchguard | ap102 firmware |
| watchguard | ap200 |
| watchguard | ap200 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit) | 2018-09-14 |
References
- http://seclists.org/fulldisclosure/2018/May/12
- https://watchguardsupport.secure.force.com/publicKB?type=KBSecurityIssues&SFDCID=kA62A0000000LIy
- https://www.exploit-db.com/exploits/45409/
- https://www.watchguard.com/wgrd-blog/new-firmware-available-ap100ap102ap200ap300-security-vulnerability-fixes
- http://seclists.org/fulldisclosure/2018/May/12
- https://watchguardsupport.secure.force.com/publicKB?type=KBSecurityIssues&SFDCID=kA62A0000000LIy
- https://www.exploit-db.com/exploits/45409/
- https://www.watchguard.com/wgrd-blog/new-firmware-available-ap100ap102ap200ap300-security-vulnerability-fixes
→ the Explorer · watch your stack · NVD