CVE-2018-17935 affects all versions of Telecrane F25 Series Radio Controls before 00.0A, stemming from the use of fixed, reproducible codes. This vulnerability allows an attacker within radio range to sniff and re-transmit commands, leading to unauthorized replay, arbitrary message spoofing, or forcing a permanent "stop" state on controlled equipment. With a CVSS score of 8.1 (High), the attack requires adjacent network access but no user interaction, resulting in high integrity and availability impacts. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 00.0aCPE matchmatch criteria | cpe:2.3:o:telecrane:f25-2s_firmware:*:*:*:*:*:*:*:* | ||
< 00.0aCPE matchmatch criteria | cpe:2.3:o:telecrane:f25-2d_firmware:*:*:*:*:*:*:*:* | ||
< 00.0aCPE matchmatch criteria | cpe:2.3:o:telecrane:f25-4s_firmware:*:*:*:*:*:*:*:* | ||
< 00.0aCPE matchmatch criteria | cpe:2.3:o:telecrane:f25-4d_firmware:*:*:*:*:*:*:*:* | ||
< 00.0aCPE matchmatch criteria | cpe:2.3:o:telecrane:f25-6s_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.