CVE-2018-6940

MEDIUM

Nat32 - CSRF

Title source: rule
STIX 2.1

Description

A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with CSRF.

Exploits (1)

exploitdb WORKING POC
by hyp3rlinx · textwebappswindows
https://www.exploit-db.com/exploits/44033

References (4)

Core 4
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44033/
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/541777/100/0/threaded

Scores

CVSS v3 6.1
EPSS 0.0809
EPSS Percentile 92.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-352 CWE-79
Status published
Products (1)
nat32/nat32 2.2
Published Feb 20, 2018
Tracked Since Feb 18, 2026