CVE-2018-6460 describes an information disclosure vulnerability in AnchorFree Hotspot Shield. The application runs an insecure web server on localhost (127.0.0.1:895) that exposes sensitive configuration data via JSONP. An unauthenticated attacker can exploit this by sending a crafted POST request to /status.js, leveraging insufficient input filtering to extract details such as VPN connection status, connected VPN server, and the user's real IP address. This vulnerability carries a CVSS v3 score of 7.5 (HIGH), indicating a network-based attack with low complexity and high confidentiality impact, requiring no user interaction or privileges. The EPSS score of 0.20389 suggests a moderate likelihood of exploitation, while the FAUCET Risk Score of 96/100 highlights its significant risk. While not listed in CISA's KEV catalog or Hot List, and lacking Metasploit or Nuclei modules, an exploit (EDB-44042) is publicly available on ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:anchorfree:hotspot_shield:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.