peter bassill · operator
$ cve CVE-2018-15555 JSON

CVE-2018-15555

9.8
CRITICAL · CVSS 3.0 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and password "admin" by using the enabled onboard UART headers.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS2.97% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-662
On CISA KEVno
Public exploitnone known
Published2019-06-28
Last modified2026-06-17

Affected (2)

VendorProduct
actiontecweb6000q
actiontecweb6000q firmware

References

→ the Explorer  ·  watch your stack  ·  NVD