Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-1151


The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers to execute arbitrary code or cause denial of service via crafted HTTP requests to toServerValue.cgi.


Published

2018-06-12T17:29:00.397

Last Modified

2024-11-21T03:59:17.530

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System westerndigital tv_live_hub_firmware 3.12.13 Yes
Hardware westerndigital tv_live_hub - No
Operating System westerndigital tv_media_player_firmware 1.03.07 Yes
Hardware westerndigital tv_media_player - No

References