CRITICAL

CVE-2018-16618

CVSS v3

9.8

CRITICAL

EPSS Score

16.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttranslate.x service on port 1668 listening for requests on localhost. Requests submitted to this service are checked for a string of random characters followed by the name of an Android activity to start. Activities are started by inserting their name into a string that is executed in a shell command. By inserting metacharacters this can be exploited to run arbitrary commands as root. The requests also match those of the HTTP protocol and can be triggered on any web page rendered on the device by requesting resources stored at an http://127.0.0.1:1668/ URI, as demonstrated by the http://127.0.0.1:1668/dacdb70556479813fab2d92896596eef?';{ping,example.org}' URL.

Technical details

Published
6/19/2019

Frequently asked questions

What is CVE-2018-16618?

VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttranslate.x service on port 1668 listening for requests on localhost. Requests submitted to this service are checked for a string of random characters followed by the name of an Android activity to start. Activities are started by inserting their name into a string that is executed in a shell command. By inserting metacharacters this can be exploited to run arbitrary commands as root. The requests also match those of the HTTP protocol and can be triggered on any web page rendered on the device by requesting resources stored at an http://127.0.0.1:1668/ URI, as demonstrated by the http://127.0.0.1:1668/dacdb70556479813fab2d92896596eef?';{ping,example.org}' URL.

Is CVE-2018-16618 actively exploited?

Active exploitation of CVE-2018-16618 has not been confirmed. The EPSS score is 16.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-16618?

CVE-2018-16618 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2018-16618 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.