ZeroHour

CVE-2018-15477

CVSS 3.0
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

myStrom WiFi Switch V1 devices before 2.66 did not sanitize a parameter received from the cloud that was used in an OS command. Malicious servers were able to run operating system commands on the device.

Vendors
mystrom
Products
wifi switch firmware
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.