CVE-2018-15486

CRITICAL

KONE Group Controller <4.6.5 - Local File Inclusion

Title source: llm
STIX 2.1

Description

An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Local File Inclusion and File modification is possible through the open HTTP interface by modifying the name parameter of the file endpoint, aka KONE-02.

Scores

CVSS v3 9.1
EPSS 0.0026
EPSS Percentile 49.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-829
Status published
Products (1)
kone/group_controller_firmware < 4.6.5
Published Sep 07, 2018
Tracked Since Feb 18, 2026