CVE-2018-10577 EXPLOIT
8.8
HIGH · CVSS 3.0 · EPSS 6.5% (pctl 94)
Patch early
A public exploit exists.
Description
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as root.
Scoring
| CVSS | 8.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.49% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-05-02 |
| Last modified | 2026-06-17 |
Affected (8)
| Vendor | Product |
|---|---|
| watchguard | ap100 |
| watchguard | ap100 firmware |
| watchguard | ap102 |
| watchguard | ap102 firmware |
| watchguard | ap200 |
| watchguard | ap200 firmware |
| watchguard | ap300 |
| watchguard | ap300 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit) | 2018-09-14 |
References
→ the Explorer · watch your stack · NVD