CVE-2018-10577 is a critical vulnerability affecting WatchGuard AP100, AP102, and AP200 devices running firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. It allows authenticated users to upload malicious code to the web root, which can then be executed with root privileges. This vulnerability has a CVSS score of 8.8 (High), indicating a severe risk of complete compromise (Confidentiality, Integrity, Availability) with low attack complexity over the network. While not listed in CISA's KEV catalog, a Metasploit module for this RCE exists (EDB-45409), suggesting potential for exploitation. Despite the availability of exploit code, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.9.15CPE matchmatch criteria | cpe:2.3:o:watchguard:ap200_firmware:*:*:*:*:*:*:*:* | ||
< 1.2.9.15CPE matchmatch criteria | cpe:2.3:o:watchguard:ap102_firmware:*:*:*:*:*:*:*:* | ||
< 1.2.9.15CPE matchmatch criteria | cpe:2.3:o:watchguard:ap100_firmware:*:*:*:*:*:*:*:* | ||
< 2.0.0.10CPE matchmatch criteria | cpe:2.3:o:watchguard:ap300_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.