Back to Database
Status published
High
CVE-2018-0639
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights...
Vulnerability Description
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via tools_firmware.cgi date parameter, time parameter, and offset parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-0639
Credits & Attribution
No credits recorded in the NVD database.
References
More from NEC Corporation
View All →CVE-2025-8153
Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5...
Medium
5.1
CVE-2025-12852
DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All...
High
8.4
CVE-2025-11546
CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and...
Critical
9.3
CVE-2025-0356
NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3...
High
7.2
CVE-2025-0355
Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm...
High
7.5
Affected Vendor
NEC Corporation
View all reports →Affected Software
HC100RC
Vulnerable Versions:
Ver1.0.1 and earlier
Timeline
Official Publish:
January 9th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.