CVE-2018-10592 describes a critical vulnerability in multiple Yokogawa STARDOM FCJ, FCN-100, FCN-RTU, and FCN-500 controller versions (R4.02 and prior) due to the use of hard-coded credentials. This flaw allows an unauthenticated attacker to gain administrative access, potentially leading to remote code execution. With a CVSS score of 9.8 (Critical), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction, resulting in complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, its high FAUCET Risk Score of 86/100, above-average EPSS score, and media coverage indicate significant concern within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= r4.02CPE matchmatch criteria | cpe:2.3:o:yokogawa:fcj_firmware:*:*:*:*:*:*:*:* | ||
<= r4.02CPE matchmatch criteria | cpe:2.3:o:yokogawa:fcn-100_firmware:*:*:*:*:*:*:*:* | ||
<= r4.02CPE matchmatch criteria | cpe:2.3:o:yokogawa:fcn-rtu_firmware:*:*:*:*:*:*:*:* | ||
<= r4.02CPE matchmatch criteria | cpe:2.3:o:yokogawa:fcn-500_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.