Vulnerability record · CVE-2018-1000049 · published 9 February 2018
CVE-2018-1000049: Claymore Dual Miner API input validation flaw enables remote code execution
Nanopool · Claymore Dual Miner
Nanopool Claymore Dual Miner 7.3 and earlier fails to properly validate input to its miner API, allowing remote code execution. The flaw is only reachable when the miner is run with read/write mode enabled, which exposes the API to command abuse.
Description
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API. The flaw can be exploited only if the software is executed with read/write mode enabled.
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with public exploits and very high EPSS, though exploitation requires the non-default read/write API mode.
What it is
Nanopool Claymore Dual Miner 7.3 and earlier fails to properly validate input to its miner API, allowing remote code execution. The flaw is only reachable when the miner is run with read/write mode enabled, which exposes the API to command abuse.
Impact
An attacker who can reach the exposed API can execute arbitrary code on the host running the miner, leading to full compromise of that system.
Attack surface
Reached over the network via the miner API (CVSS AV:N) and requires low privileges (PR:L) with no user interaction (UI:N); exploitation is conditional on the software being started with read/write mode enabled.
Exploitation
Not listed in CISA KEV, but public exploit references exist (ExploitDB, Packet Storm, Rapid7 module) and EPSS is very high at 0.76944 (99.5th percentile), indicating likely active exploitation.
What to do
- Upgrade Claymore Dual Miner to a version later than 7.3 if available; the record does not list fixed versions.
- Do not run the miner with read/write API mode enabled; use read-only mode where possible.
- Restrict network access to the miner API port to trusted hosts only, and never expose it to the internet.
- Isolate mining hosts on a segmented network with no access to sensitive systems or data.
- Monitor and block known exploit traffic and tooling targeting the Claymore API.
Detection
- Monitor miner API logs and network traffic for unexpected or malformed API requests.
- Alert on processes spawned by the miner binary, especially shell or scripting interpreters.
- Detect outbound connections from mining hosts to unknown or suspicious destinations.
- Search for known exploit artifacts or tooling associated with Claymore Dual Miner RCE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-1000049 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1000049), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.