Back to Database
Status published
Critical
CVE-2018-15556
The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows...
Vulnerability Description
The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-15556
Credits & Attribution
No credits recorded in the NVD database.
References
More from actiontec
View All →CVE-2019-12789
An issue was discovered on Actiontec T2200H T2200H-31.128L.08 devices, as...
Medium
6.8
CVE-2018-19922
Persistent Cross-Site Scripting (XSS) in the advancedsetup_websiteblocking.html Website Blocking page...
Medium
6.1
CVE-2018-15557
An issue was discovered in the Quantenna WiFi Controller on...
High
8.8
CVE-2018-15555
On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login...
Critical
9.8
CVE-2018-10252
An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices....
High
8.1
Affected Vendor
actiontec
View all reports →Affected Software
web6000q firmware
Vulnerable Versions:
1.1.02.22
Timeline
Official Publish:
June 27th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.