Vulnerabilities > Cerio

DATE CVE VULNERABILITY TITLE RISK
2019-06-18 CVE-2018-18852 OS Command Injection vulnerability in Cerio Dt-300N Firmware 1.1.12/1.1.6
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.
network
low complexity
cerio CWE-78
8.8