CVE-2018-17935

HIGH

Telecrane F25 Series Radio Controls <00.0A - Command Injection

Title source: llm
STIX 2.1

Description

All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.

Scores

CVSS v3 8.1
EPSS 0.0026
EPSS Percentile 49.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-294
Status published
Products (11)
telecrane/f25-10d_firmware < 00.0a
telecrane/f25-10s_firmware < 00.0a
telecrane/f25-2d_firmware < 00.0a
telecrane/f25-2s_firmware < 00.0a
telecrane/f25-4d_firmware < 00.0a
telecrane/f25-4s_firmware < 00.0a
telecrane/f25-60_firmware < 00.0a
telecrane/f25-6d_firmware < 00.0a
telecrane/f25-6s_firmware < 00.0a
telecrane/f25-8d_firmware < 00.0a
... and 1 more
Published Oct 24, 2018
Tracked Since Feb 18, 2026