CVE-2018-15556

CRITICAL

Actiontec WEB6000Q Firmware 1.1.02.22 - Unauthenticated Root Access via UART

Title source: llm
STIX 2.1

Description

The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers.

References (2)

Core 2
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2019/Jun/1

Scores

CVSS v3 9.8
EPSS 0.0326
EPSS Percentile 86.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
actiontec/web6000q_firmware 1.1.02.22
Published Jun 27, 2019
Tracked Since Feb 18, 2026