CVE-2018-20162

CRITICAL

Digi TransPort LR54 <4.4.0.26 - Privilege Escalation

Title source: llm

Description

Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root.

Exploits (1)

nomisec WORKING POC
by stigtsp · poc
https://github.com/stigtsp/CVE-2018-20162-digi-lr54-restricted-shell-escape

Scores

CVSS v3 9.9
EPSS 0.0395
EPSS Percentile 88.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
digi/transport_lr54_firmware < 4.4.0.26
Published Mar 21, 2019
Tracked Since Feb 18, 2026