CVE-2018-18473
9.8
CRITICAL · CVSS 3.0 · EPSS 5.6% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow attackers to enable an SSH daemon via the "kankichi" or "kamiyo4" password to the _secret1.htm URI. Subsequently, the default password of root for the root account allows an attacker to conduct remote code execution and as a result take over the system.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.65% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-798 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-03-21 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| patlite | nbm-d88n |
| patlite | nbm-d88n firmware |
| patlite | nhl-3fb1 |
| patlite | nhl-3fb1 firmware |
| patlite | nhl-3fv1n |
| patlite | nhl-3fv1n firmware |
References
→ the Explorer · watch your stack · NVD