CVE-2018-10080 describes a critical vulnerability in Secutech RiS-11, RiS-22, and RiS-33 devices running firmware V5.07.52_es_FRI01, allowing unauthorized DNS setting changes. This vulnerability, rated 8.6 HIGH on the CVSS scale, permits unauthenticated attackers to modify DNS configurations remotely with low complexity, potentially leading to DNS hijacking or other network disruptions. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media attention, including a SecurityWeek article mentioning a new exploit kit targeting SOHO routers, suggesting potential for future exploitation. It is not currently listed in CISA's KEV catalog or on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.07.52_es_fri01CPE matchmatch criteria | cpe:2.3:o:secutech_project:ris-11_firmware:5.07.52_es_fri01:*:*:*:*:*:*:* | ||
5.07.52_es_fri01CPE matchmatch criteria | cpe:2.3:o:secutech_project:ris-22_firmware:5.07.52_es_fri01:*:*:*:*:*:*:* | ||
5.07.52_es_fri01CPE matchmatch criteria | cpe:2.3:o:secutech_project:ris-33_firmware:5.07.52_es_fri01:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.