CVE-2018-20394

CRITICAL

Thomson DWG849 DWG850-4 DWG855 TWG870 - Unauthenticated Credential Exposure via SNMP OID Requests

Title source: llm
STIX 2.1

Description

Thomson DWG849 STC0.01.16, DWG850-4 ST9C.05.25, DWG855 ST80.20.26, and TWG870 STB2.01.36 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

Scores

CVSS v3 9.8
EPSS 0.0151
EPSS Percentile 71.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522
Status published
Products (4)
technicolor/dwg849_firmware stc0.01.16
technicolor/dwg850-4_firmware st9c.05.25
technicolor/dwg855_firmware st80.20.26
technicolor/twg870_firmware stb2.01.36
Published Dec 23, 2018
Tracked Since Feb 18, 2026