peter bassill · operator
$ cve CVE-2018-9245 JSON

CVE-2018-9245 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 4% (pctl 90)

Patch early

A public exploit exists.

Description

The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.98% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2018-04-22
Last modified2026-06-17

Affected (1)

VendorProduct
ericssonlgipecs nms

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD