HIGH

CVE-2019-18396

CVSS v3

7.2

HIGH

EPSS Score

56.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping module in the Web Interface in OI_Fw_V20 allows remote attackers to execute arbitrary OS commands in the pingAddr parameter to mnt_ping.cgi. NOTE: This may overlap CVE-2017–14127.

Technical details

Published
10/31/2019

Frequently asked questions

What is CVE-2019-18396?

An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping module in the Web Interface in OI_Fw_V20 allows remote attackers to execute arbitrary OS commands in the pingAddr parameter to mnt_ping.cgi. NOTE: This may overlap CVE-2017–14127.

Is CVE-2019-18396 actively exploited?

Active exploitation of CVE-2019-18396 has not been confirmed. The EPSS score is 56.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-18396?

CVE-2019-18396 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2019-18396 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.