cvedb.io
CVE-2018-16591
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2018-09-10T17:29:00.587 · Last modified 2026-06-17T01:44:30.960

Summary

FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.

Affected products

furuno — felcom_250_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when furuno ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.