10
CVSSv2

CVE-2018-15477

Published: 30/08/2018 Updated: 09/11/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

myStrom WiFi Switch V1 devices prior to 2.66 did not sanitize a parameter received from the cloud that was used in an OS command. Malicious servers were able to run operating system commands on the device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mystrom wifi_switch_firmware