CVE-2018-16739

An issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, and thus execute code arbitrarily with root privileges.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 46%
VendorProductVersion
abustvip_10000_firmware
-
abustvip_10001_firmware
-
abustvip_10005_firmware
-
abustvip_10005a_firmware
-
abustvip_10005b_firmware
-
abustvip_10050_firmware
-
abustvip_10051_firmware
-
abustvip_10055a_firmware
-
abustvip_10055b_firmware
-
abustvip_10500_firmware
-
abustvip_10550_firmware
-
abustvip_11000_firmware
-
abustvip_11050_firmware
-
abustvip_11500_firmware
-
abustvip_11501_firmware
-
abustvip_11502_firmware
-
abustvip_11550_firmware
-
abustvip_11551_firmware
-
abustvip_11552_firmware
-
abustvip_20000_firmware
-
abustvip_20050_firmware
-
abustvip_20500_firmware
-
abustvip_20550_firmware
-
abustvip_21000_firmware
-
abustvip_21050_firmware
-
abustvip_21500_firmware
-
abustvip_21501_firmware
-
abustvip_21502_firmware
-
abustvip_21550_firmware
-
abustvip_21551_firmware
-
abustvip_21552_firmware
-
abustvip_22500_firmware
-
abustvip_31000_firmware
-
abustvip_31001_firmware
-
abustvip_31050_firmware
-
abustvip_31500_firmware
-
abustvip_31501_firmware
-
abustvip_31550_firmware
-
abustvip_31551_firmware
-
abustvip_32500_firmware
-
abustvip_51500_firmware
-
abustvip_51550_firmware
-
abustvip_71500_firmware
-
abustvip_71501_firmware
-
abustvip_71550_firmware
-
abustvip_71551_firmware
-
abustvip_72500_firmware
-
𝑥
= Vulnerable software versions