CVE-2018-11682 - CVE House
Back to Database
Status published Unknown CVE-2018-11682

Default and unremovable support credentials allow attackers to gain total...

Vulnerability Description

Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machine

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-11682

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

stanza firmware, radiora 2 firmware, homeworks qs firmware
Vulnerable Versions:
Unknown

Timeline

Official Publish: June 2nd, 2018
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.