CVE-2018-6941

HIGH

Nat32 - CSRF

Title source: rule
STIX 2.1

Description

A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with XSS.

Exploits (1)

exploitdb WORKING POC
by hyp3rlinx · textwebappswindows
https://www.exploit-db.com/exploits/44034

References (3)

Core 3
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44034/

Scores

CVSS v3 8.8
EPSS 0.0255
EPSS Percentile 85.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
nat32/nat32 2.2
Published Feb 20, 2018
Tracked Since Feb 18, 2026