CVE-2018-16201

HIGH

Toshiba HEM-GW16A and HEM-GW26A < 1.2.9 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segment to login to the administrators settings screen and change the configuration or execute arbitrary OS commands.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory x_refsource_jvn
https://jvn.jp/en/jp/JVN99810718/index.html

Scores

CVSS v3 8.8
EPSS 0.0060
EPSS Percentile 44.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (2)
toshiba/hem-gw16a_firmware < 1.2.9
toshiba/hem-gw26a_firmware < 1.2.9
Published Jan 09, 2019
Tracked Since Feb 18, 2026