CVE-2018-0512
MEDIUMIodata Hdl-xr Firmware < 2.01 - OS Command Injection
Title source: ruleDescription
Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry third-party-advisory
x_refsource_jvn
https://jvn.jp/en/jp/JVN36048131/index.html
Vendor Advisory x_refsource_confirm
http://www.iodata.jp/support/information/2018/magicalfinder/
Scores
CVSS v3
6.8
EPSS
0.0067
EPSS Percentile
47.2%
Attack Vector
ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (45)
iodata/bx-vp1_firmware
< 2.01
iodata/gv-ntx1_firmware
< 1.02.00
iodata/gv-ntx2_firmware
< 1.02.00
iodata/hdl-a_firmware
< 1.26
iodata/hdl-ah_firmware
< 1.26
iodata/hdl-gt_firmware
< 1.37
iodata/hdl-gtr_firmware
< 1.37
iodata/hdl-t_firmware
< 1.12
iodata/hdl-xr2u_firmware
< 2.01
iodata/hdl-xr2uw_firmware
< 2.01
... and 35 more
Published
Feb 08, 2018
Tracked Since
Feb 18, 2026