peter bassill · operator
$ cve CVE-2018-10576 JSON

CVE-2018-10576 EXPLOIT

7.8
HIGH · CVSS 3.0 · EPSS 1.5% (pctl 73)

Patch early

A public exploit exists.

Description

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a local system account (instead of the dedicated web-only user).

Scoring

CVSS7.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS1.47% — more likely to be exploited than 73% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2018-04-30
Last modified2026-06-17

Affected (6)

VendorProduct
watchguardap100
watchguardap100 firmware
watchguardap102
watchguardap102 firmware
watchguardap200
watchguardap200 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD