Back
CVE-2018-20122
CRITICAL
The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary that is vulnerable to a command injection vulnerability that can be exploited to achieve remote code execution with root privileges. No authentication is required in order to trigger the vulnerability.
Published: Feb 21, 2019
Modified: Jun 17, 2026
CWE-78
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| fastweb | fastgate_firmware | * |
GitHub Security Advisory GHSA-93p5-p6gm-m2rg
The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05...
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
4.82%
Top 9% most likely to be exploited
Threat Score
40.6 / 100
Data Sources
NVD
EPSS
GitHub