CVE-2018-11681
9.8
CRITICAL · CVSS 3.1 · EPSS 4.3% (pctl 91)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machine
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.3% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-798 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-06-02 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| lutron | homeworks qs |
| lutron | homeworks qs firmware |
| lutron | radiora 2 |
| lutron | radiora 2 firmware |
| lutron | stanza |
| lutron | stanza firmware |
References
- http://sadfud.me/explotos/CVE-2018-11629
- http://www.lutron.com/TechnicalDocumentLibrary/040249.pdf
- https://reversecodes.wordpress.com/2018/06/02/0-day-tomando-el-control-de-las-instalaciones-de-la-nasa-en-cabo-canaveral/
- http://sadfud.me/explotos/CVE-2018-11629
- http://www.lutron.com/TechnicalDocumentLibrary/040249.pdf
- https://reversecodes.wordpress.com/2018/06/02/0-day-tomando-el-control-de-las-instalaciones-de-la-nasa-en-cabo-canaveral/
→ the Explorer · watch your stack · NVD