CVE-2018-13862 is a critical authentication bypass vulnerability affecting Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 and its firmware. An unauthenticated remote attacker can reset authentication by sending a specific GET request to the "/xml/system/setAttribute.xml" URL, allowing unauthorized login. This vulnerability has a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog or showing widespread community discussion, a public exploit (EDB-45063) exists, indicating potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.53CPE matchmatch criteria | cpe:2.3:o:trivum:webtouch_setup_v9_firmware:2.53:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.