PT-2018-9973 · Watchguard · Watchguard Ap200+2

Stephen Shkardoon

·

Published

2018-04-30

·

Updated

2018-09-16

·

CVE-2018-10575

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WatchGuard AP100 versions prior to 1.2.9.15 WatchGuard AP102 versions prior to 1.2.9.15 WatchGuard AP200 versions prior to 1.2.9.15
Description: An issue exists due to hardcoded credentials for an unprivileged SSH account with a shell of /bin/false.
Recommendations: For WatchGuard AP100 versions prior to 1.2.9.15, update the firmware to version 1.2.9.15 or later. For WatchGuard AP102 versions prior to 1.2.9.15, update the firmware to version 1.2.9.15 or later. For WatchGuard AP200 versions prior to 1.2.9.15, update the firmware to version 1.2.9.15 or later.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10575

Affected Products

Watchguard Ap100
Watchguard Ap102
Watchguard Ap200