Record summary

CVE-2018-14916 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALLoytec LGATE-902 <6.4.2 - Local File InclusionCVSS 9.1

Loytec LGATE-902 versions prior to 6.4.2 suffers from a local file inclusion vulnerability.

Impact

An attacker can exploit this vulnerability to read sensitive files on the device.

Remediation

Upgrade the Loytec LGATE-902 device to version 6.4.2 or later to mitigate the vulnerability.

WeaknessesCWE-732
Authors0x_Akoko
Template tagscve2018cveloyteclfipacketstormseclistsxssvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CPE: cpe:2.3:h:loytec:lgate-902:-:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4