peter bassill · operator
$ cve CVE-2018-11692 JSON

CVE-2018-11692

9.8
CRITICAL · CVSS 3.0 · EPSS 4.4% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a customer keeps the default settings without using the countermeasures and best practices shown in the documentation

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.4% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2018-06-04
Last modified2026-06-17

Affected (8)

VendorProduct
canonlbp3370
canonlbp3370 firmware
canonlbp3460
canonlbp3460 firmware
canonlbp6650
canonlbp6650 firmware
canonlbp7750c
canonlbp7750c firmware

References

→ the Explorer  ·  watch your stack  ·  NVD