CVE-2018-16158 is a critical vulnerability affecting Eaton Power Xpert Meter 4000, 6000, and 8000 devices prior to version 13.4.0.10. It stems from the use of a shared, easily accessible SSH private key across all installations, enabling remote attackers to gain root access. With a CVSS score of 9.8 (Critical), this vulnerability allows unauthenticated remote attackers to achieve full compromise (confidentiality, integrity, availability) with low attack complexity. While not listed in CISA's KEV catalog or showing active exploitation in the wild, a Metasploit module exists for scanning and exploitation, indicating readily available exploit code. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.4.0.10CPE matchmatch criteria | cpe:2.3:o:eaton:power_xpert_meter_4000_firmware:*:*:*:*:*:*:*:* | ||
< 13.4.0.10CPE matchmatch criteria | cpe:2.3:o:eaton:power_xpert_meter_6000_firmware:*:*:*:*:*:*:*:* | ||
< 13.4.0.10CPE matchmatch criteria | cpe:2.3:o:eaton:power_xpert_meter_8000_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.