CVE-2018-9162

CRITICAL

Contec Smart Home 4.15 - Unauthenticated User Management via new_user.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-9162. PoCs published by Z3ro0ne.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated password reset vulnerability in Contec smart home version 4.15. It allows an attacker to reset the admin password, create new users, edit existing users, and delete users without authentication.

Description

Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors.

Exploits (1)

exploitdb WORKING POC
by Z3ro0ne · textwebappshardware
https://www.exploit-db.com/exploits/44295

This exploit demonstrates an unauthenticated password reset vulnerability in Contec smart home version 4.15. It allows an attacker to reset the admin password, create new users, edit existing users, and delete users without authentication.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Contec smart home 4.15
No auth needed
Prerequisites: Network access to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44295/

Scores

CVSS v3 9.8
EPSS 0.0236
EPSS Percentile 81.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (1)
contec-touch/smart_home_firmware 4.15
Published Mar 31, 2018
Tracked Since Feb 18, 2026