CVE-2018-20162
9.9
CRITICAL · CVSS 3.0 · EPSS 4.1% (pctl 90)
In your normal cycle
Critical by CVSS (9.9), but no sign of active exploitation.
Description
Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root.
Scoring
| CVSS | 9.9 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 4.09% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-03-21 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| digi | transport lr54 |
| digi | transport lr54 firmware |
References
- http://packetstormsecurity.com/files/151719/Digi-TransPort-LR54-Restricted-Shell-Escape.html
- https://blog.hackeriet.no/cve-2018-20162-digi-lr54-restricted-shell-escape/
- https://seclists.org/bugtraq/2019/Feb/34
- http://packetstormsecurity.com/files/151719/Digi-TransPort-LR54-Restricted-Shell-Escape.html
- https://blog.hackeriet.no/cve-2018-20162-digi-lr54-restricted-shell-escape/
- https://seclists.org/bugtraq/2019/Feb/34
→ the Explorer · watch your stack · NVD