CVE-2018-12073 describes a medium-severity vulnerability in Eminent EM4544 9.10 devices, where the web interface allows users to change their password without first providing the current one. This flaw, rated 5.3 CVSS, could enable an attacker with network access to reset the administrator password, potentially through social engineering or an unattended workstation, leading to unauthorized access. While the vulnerability has a low EPSS score and no known active exploitation, public exploit code, or significant community discussion, it still poses a risk if exploited in conjunction with other attack vectors like XSS.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.10CPE matchmatch criteria | cpe:2.3:a:eminent-online:em4544:9.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.