peter bassill · operator
$ cve CVE-2018-12980 JSON

CVE-2018-12980 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 29.8% (pctl 98)

Patch early

A public exploit exists.

Description

An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS29.8% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2018-07-12
Last modified2026-06-17

Affected (8)

VendorProduct
wago762-3000
wago762-3000 firmware
wago762-3001
wago762-3001 firmware
wago762-3002
wago762-3002 firmware
wago762-3003
wago762-3003 firmware

Public exploits

SourceTitleDate
exploit-dbWAGO e!DISPLAY 7300T - Multiple Vulnerabilities2018-07-13

References

→ the Explorer  ·  watch your stack  ·  NVD