CVE-2018-16618 is a critical remote command execution vulnerability affecting VTech Storio Max devices running firmware versions prior to 56.D3JM6. It allows an attacker to execute arbitrary commands as root by injecting shell metacharacters into an Android activity name via the exposed storeintenttranslate.x service. This vulnerability has a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential impact is severe.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 56.d3jm6CPE matchmatch criteria | cpe:2.3:o:vtech:storio_max_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.