CVE-2018-18852 is an OS command injection vulnerability affecting Cerio DT-300N devices running firmware versions 1.1.6 through 1.1.12. The flaw stems from improper input validation within the web interface's PING feature, allowing attackers to inject arbitrary commands via the Save.cgi script. This vulnerability carries a high CVSS score of 8.8, indicating a critical risk with low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. While exploited in the wild in October 2018, there is currently no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.6, <= 1.1.12CPE matchmatch criteria | cpe:2.3:o:cerio:dt-300n_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.