CVE-2018-18871

CRITICAL

Gigasetpro Maxwell Basic Firmware - Password Reset Weakness

Title source: rule
STIX 2.1

Description

Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password).

Scores

CVSS v3 9.8
EPSS 0.0062
EPSS Percentile 70.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-640
Status published
Products (1)
gigasetpro/maxwell_basic_firmware 2.22.7
Published Dec 20, 2018
Tracked Since Feb 18, 2026