CVE Database
/

CVE-2018-0666

Back to search

CVE-2018-0666

Published: Jan 9, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed arbitrary scripts to the configuration data through a certain form field of the configuration page, which may be executed on another administrative user's web browser. This is a different vulnerability from CVE-2018-0665.

VendorProductVersions

Yamaha Corporation

Yamaha Broadband VoIP Router RT57i

affected
Rev.8.00.95 and earlier

Yamaha Corporation

Yamaha Broadband VoIP Router RT58i

affected
Rev.9.01.51 and earlier

Yamaha Corporation

Yamaha Broadband VoIP Router NVR500

affected
Rev.11.00.36 and earlier

Yamaha Corporation

Yamaha Gigabit VPN Router RTX810

affected
Rev.11.01.31 and earlier

Yamaha Corporation

Yamaha Firewall FWX120

affected
Rev.11.03.25 and earlier

NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION

Biz Box Router N58i, N500, NVR500, and RTX810

affected
n/a

NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION

Biz Box Router N58i, and N500

affected
n/a

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now