CVE-2018-10088 is a critical buffer overflow vulnerability affecting XiongMai uc-httpd 1.0.0, a web server often found in IoT devices. This flaw allows unauthenticated remote attackers to execute arbitrary code with maximum impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8. While not listed in CISA's KEV catalog, exploit code is publicly available on ExploitDB and Nuclei templates exist, suggesting a high likelihood of exploitation. The vulnerability has garnered significant community attention and media coverage, including reports of its use by malware like Satori and BotenaGo to compromise IoT devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:xiongmaitech:uc-httpd:1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.