CVE-2018-0628 describes a critical OS command injection vulnerability affecting NEC Aterm WG1200HP firmware versions 1.0.31 and earlier. An attacker with administrative privileges can execute arbitrary operating system commands by manipulating HTTP requests and responses. This vulnerability carries a high CVSSv3 score of 7.2, indicating a severe impact with high confidentiality, integrity, and availability compromise, requiring prior authentication but being network-exploitable with low attack complexity. While no public exploits (Metasploit, Nuclei, ExploitDB) or active exploitation (KEV) have been identified, and community discussion is minimal, the potential for a highly privileged attacker to compromise the device remains significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.31CPE matchmatch criteria | cpe:2.3:o:nec:aterm_wg1200hp_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.