Vulnerability Details CVE-2018-18879
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.5%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2018-18879
-
cpe:2.3:h:columbiaweather:weather_microserver:-
-
cpe:2.3:o:columbiaweather:weather_microserver_firmware:ms_2.6.9900