CVE-2018-10088

CRITICAL EXPLOITED IN THE WILD NUCLEI

XiongMai uc-httpd 1.0.0 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-10088 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including Andrew Watson. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in XiongMai uc-httpd 1.0.0 by sending a malformed POST request with an oversized username parameter. The payload consists of 85 'A' characters, which may crash the service or potentially allow arbitrary code execution under specific conditions.

Description

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

Exploits (1)

exploitdb WORKING POC
by Andrew Watson · pythonwebappshardware
https://www.exploit-db.com/exploits/44864

This exploit demonstrates a buffer overflow vulnerability in XiongMai uc-httpd 1.0.0 by sending a malformed POST request with an oversized username parameter. The payload consists of 85 'A' characters, which may crash the service or potentially allow arbitrary code execution under specific conditions.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Theoretical
Target: XiongMai uc-httpd 1.0.0
No auth needed
Prerequisites: Network access to TCP port 81 on the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

XiongMai uc-httpd 1.0.0 - Buffer Overflow
CRITICALVERIFIEDby 0x_Akoko
Shodan: cpe:"cpe:2.3:a:xiongmaitech:uc-httpd"

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44864/

Scores

CVSS v3 9.8
EPSS 0.4039
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2018-06-15
InTheWild.io 2021-11-11
CWE
CWE-119
Status published
Products (1)
xiongmaitech/uc-httpd 1.0.0
Published Jun 08, 2018
Tracked Since Feb 18, 2026