CRITICAL

CVE-2018-1151

CVSS v3

9.8

CRITICAL

EPSS Score

25.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers to execute arbitrary code or cause denial of service via crafted HTTP requests to toServerValue.cgi.

Technical details

Published
6/12/2018

Frequently asked questions

What is CVE-2018-1151?

The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers to execute arbitrary code or cause denial of service via crafted HTTP requests to toServerValue.cgi.

Is CVE-2018-1151 actively exploited?

Active exploitation of CVE-2018-1151 has not been confirmed. The EPSS score is 25.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-1151?

CVE-2018-1151 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2018-1151 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.