peter bassill · operator
$ cve CVE-2018-10577 JSON

CVE-2018-10577 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 6.5% (pctl 94)

Patch early

A public exploit exists.

Description

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as root.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS6.49% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2018-05-02
Last modified2026-06-17

Affected (8)

VendorProduct
watchguardap100
watchguardap100 firmware
watchguardap102
watchguardap102 firmware
watchguardap200
watchguardap200 firmware
watchguardap300
watchguardap300 firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD