CVE-2018-3969 describes an exploitable vulnerability in the verified boot protection of the CUJO Smart Firewall, allowing arbitrary shell commands to be injected into dhcpd.conf, persisting across reboots and firmware updates. This local vulnerability (AV:L) has a CVSS score of 7.8 (High), indicating high impact on confidentiality, integrity, and availability, requiring a local attacker with write access to /config/dhcpd.conf. Despite its severity, there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7003CPE matchmatch criteria | cpe:2.3:a:getcujo:smart_firewall:7003:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.