CVE-2018-11681 Details
Description
Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machine
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 23, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://sadfud.me/explotos/CVE-2018-11629 | CVE | Third Party Advisory |
| https://reversecodes.wordpress.com/2018/06/02/0-day-tomando-el-control-de-las-instalaciones-de-la-nasa-en-cabo-canaveral/ | CVE | MitigationThird Party Advisory |
| http://www.lutron.com/TechnicalDocumentLibrary/040249.pdf | CVE | |
| http://sadfud.me/explotos/CVE-2018-11629 | [email protected] | Third Party Advisory |
| https://reversecodes.wordpress.com/2018/06/02/0-day-tomando-el-control-de-las-instalaciones-de-la-nasa-en-cabo-canaveral/ | [email protected] | MitigationThird Party Advisory |
| http://www.lutron.com/TechnicalDocumentLibrary/040249.pdf | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
| CWE-798 | Use of Hard-coded Credentials | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| lutron stanza firmware | All versions |
CPE
Remediation
| |
| lutron stanza | All versions |
CPE
Remediation
| |
| lutron radiora 2 firmware | All versions |
CPE
Remediation
| |
| lutron radiora 2 | All versions |
CPE
Remediation
| |
| lutron homeworks qs firmware | All versions |
CPE
Remediation
| |
| lutron homeworks qs | All versions |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Aug 5, 2024 | CVE Modified | [email protected] |
| Jul 3, 2024 | CVE Modified | CISA-ADP |
| Jun 4, 2024 | CVE Modified | [email protected] |
| May 17, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 11, 2024 | CVE Modified | [email protected] |
| Mar 21, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Jun 27, 2019 | CVE Modified | [email protected] |
| Jul 20, 2018 | Initial Analysis | [email protected] |
| Jun 9, 2018 | CVE Modified | [email protected] |