CVE-2018-11681
Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machine
Published:Jun 2, 2018
Last Modified:Nov 21, 2024
EPS:Jun 2, 2018
EPSS Score:0.02832
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Lutron
Product
Homeworks Qs
Lutron
Homeworks Qs
Vendor
Lutron
Product
Homeworks Qs Firmware
Lutron
Homeworks Qs Firmware
Vendor
Lutron
Product
Radiora 2
Lutron
Radiora 2
Vendor
Lutron
Product
Radiora 2 Firmware
Lutron
Radiora 2 Firmware
Vendor
Lutron
Product
Stanza
Lutron
Stanza
Vendor
Lutron
Product
Stanza Firmware
Lutron
Stanza Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
