CVE-2018-0099 describes a command injection vulnerability in the web management GUI of Cisco D9800 Network Transport Receivers. An authenticated, remote attacker can exploit insufficient input validation to inject crafted arguments into GUI commands, leading to arbitrary command execution on the underlying BusyBox operating system. This vulnerability has a CVSS score of 8.8 (High) due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability, requiring valid user credentials. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the FAUCET Risk Score indicates a significant threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:d9800_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.