peter bassill · operator
$ cve CVE-2018-20220 JSON

CVE-2018-20220 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 15.4% (pctl 97)

Patch early

A public exploit exists.

Description

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication. An attacker is able to view these pages before being authenticated, and some of these pages may disclose sensitive information.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS15.36% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploityes
Published2019-03-21
Last modified2026-06-17

Affected (6)

VendorProduct
teracueenc-400 hdmi
teracueenc-400 hdmi firmware
teracueenc-400 hdmi2
teracueenc-400 hdmi2 firmware
teracueenc-400 hdsdi
teracueenc-400 hdsdi firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD