peter bassill · operator
$ cve CVE-2018-20162 JSON

CVE-2018-20162

9.9
CRITICAL · CVSS 3.0 · EPSS 4.1% (pctl 90)

In your normal cycle

Critical by CVSS (9.9), but no sign of active exploitation.

Description

Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root.

Scoring

CVSS9.9 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS4.09% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2019-03-21
Last modified2026-06-17

Affected (2)

VendorProduct
digitransport lr54
digitransport lr54 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD