CVE-2018-17935
HIGHTelecrane F25 Series Radio Controls <00.0A - Command Injection
Title source: llmDescription
All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/105732
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-18-296-03
Scores
CVSS v3
8.1
EPSS
0.0066
EPSS Percentile
46.7%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Details
CWE
CWE-294
Status
published
Products (11)
telecrane/f25-10d_firmware
< 00.0a
telecrane/f25-10s_firmware
< 00.0a
telecrane/f25-2d_firmware
< 00.0a
telecrane/f25-2s_firmware
< 00.0a
telecrane/f25-4d_firmware
< 00.0a
telecrane/f25-4s_firmware
< 00.0a
telecrane/f25-60_firmware
< 00.0a
telecrane/f25-6d_firmware
< 00.0a
telecrane/f25-6s_firmware
< 00.0a
telecrane/f25-8d_firmware
< 00.0a
... and 1 more
Published
Oct 24, 2018
Tracked Since
Feb 18, 2026