CVE-2018-18871
CRITICALGigasetpro Maxwell Basic Firmware - Password Reset Weakness
Title source: ruleDescription
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password).
Scores
CVSS v3
9.8
EPSS
0.0062
EPSS Percentile
70.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-640
Status
published
Products (1)
gigasetpro/maxwell_basic_firmware
2.22.7
Published
Dec 20, 2018
Tracked Since
Feb 18, 2026