CVE-2018-18473
Estado: ModificadaCrítica (9.8)—
A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow attackers to enable an SSH daemon via the "kankichi" or "kamiyo4" password to the _secret1.htm URI. Subsequently, the default password of root for the root account allows an attacker to conduct remote code execution and as a result take over the system.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.65%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-798
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-18473",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2019-03-21T16:00:28.467",
"references": [
{
"url": "https://herolab.usd.de/wp-content/uploads/sites/4/usd20180020.txt",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.patlite.com/support/Security_Informationtest.html",
"source": "cve@mitre.org"
},
{
"url": "https://herolab.usd.de/wp-content/uploads/sites/4/usd20180020.txt",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.patlite.com/support/Security_Informationtest.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A hidden backdoor on PATLITE NH-FB Series devices with firmware version 1.45 or earlier, NH-FV Series devices with firmware version 1.10 or earlier, and NBM Series devices with firmware version 1.09 or earlier allow attackers to enable an SSH daemon via the \"kankichi\" or \"kamiyo4\" password to the _secret1.htm URI. Subsequently, the default password of root for the root account allows an attacker to conduct remote code execution and as a result take over the system."
},
{
"lang": "es",
"value": "Una puerta trasera oculta en los dispositivos de la serie PATLITE NH-FB con la versión de firmware 1.45 o versiones anteriores, los dispositivos de la serie NH-FV con la versión de firmware 1.10 o versiones anteriores y los dispositivos de la serie NBM con la versión de firmware 1.09 o versiones anteriores permiten a los atacantes habilitar un demonio SSH mediante las contraseñas \"kankichi\" \"o\" kamiyo4 \" en el URI _secret1.htm. Posteriormente, la contraseña por defecto de root para la cuenta root permite que un atacante ejecute código de forma remota y, como resultado, tome el control del sistema."
}
],
"lastModified": "2026-06-17T01:47:21.553",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:patlite:nbm-d88n_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28FD38CB-B9E6-47E9-BE3D-6ADC912AAE6C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:patlite:nbm-d88n:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BF688BD9-EA36-4D9E-A84D-942E181C131A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:patlite:nhl-3fb1_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F9D15C13-9926-4600-8004-2962B355982E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:patlite:nhl-3fb1:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "632A5C13-610D-4109-BA54-04CF9B982F78"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:patlite:nhl-3fv1n_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7471D7C-8D6F-43AC-8615-CB11762C9E84"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:patlite:nhl-3fv1n:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0732F85A-09FA-4731-972D-078509CC05DA"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}