peter bassill · operator
$ cve CVE-2018-12981 JSON

CVE-2018-12981 EXPLOIT

5.4
MEDIUM · CVSS 3.1 · EPSS 5.2% (pctl 92)

Patch early

A public exploit exists.

Description

An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenticated and unauthenticated users by sending special crafted requests to the web server allowing injecting code within the WBM. The code will be rendered and/or executed in the browser of the user's browser.

Scoring

CVSS5.4 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS5.18% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2018-07-12
Last modified2026-06-17

Affected (8)

VendorProduct
wago762-3000
wago762-3000 firmware
wago762-3001
wago762-3001 firmware
wago762-3002
wago762-3002 firmware
wago762-3003
wago762-3003 firmware

Public exploits

SourceTitleDate
exploit-dbWAGO e!DISPLAY 7300T - Multiple Vulnerabilities2018-07-13

References

→ the Explorer  ·  watch your stack  ·  NVD