← Vulnerability feed

Vulnerability record · CVE-2018-12526 · published 21 June 2018

CVE-2018-12526: Telesquare sdt-cs3b1 firmware hard-coded credentials vulnerability

Telesquare · Sdt Cs3b1 Firmware

Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET using a hardcoded account.

9.8 CVSS 3.0 Critical EPSS 2.3% · top 17.4% CWE-798 · Hard-coded credentials
9.8CVSS 3.0 base score, v2 10.0
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Telesquare SDT-CS3B1 and SDT-CW3B1 devices through 1.2.0 have a default factory account. Remote attackers can obtain access to the device via TELNET using a hardcoded account.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-12526 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-46422Telesquare SDT-CW3B1 router OS command injectionTelesquare SDT-CW3B1 1.1.0 contains an OS command injection flaw (CWE-78) that lets a remote attacker run arbitrary operating system commands. The vu…EPSS 94%analysed9.3CVE-2017-20223Telesquare sdt-cs3b1 firmware insecure direct object reference vulnerabilityTelesquare SKT LTE Router SDT-CS3B1 firmware version 1.2.0 contains an insecure direct object reference vulnerability that allows attackers to bypass…EPSS 0.52%9.3CVE-2017-20224Telesquare sdt-cs3b1 firmware unrestricted file upload vulnerabilityTelesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload mal…EPSS 1.0%8.7CVE-2017-20222Telesquare sdt-cs3b1 firmware missing authentication for critical function vulnerabilityTelesquare SKT LTE Router SDT-CS3B1 software version 1.2.0 contains an unauthenticated remote reboot vulnerability that allows attackers to trigger d…EPSS 0.71%5.3CVE-2017-20221Telesquare sdt-cs3b1 firmware cross-site request forgery vulnerabilityTelesquare SKT LTE Router SDT-CS3B1 version 1.2.0 contains a cross-site request forgery vulnerability that allows authenticated attackers to execute …EPSS 0.29%10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed6.5CVE-2019-6693FortiOS hard-coded key exposes backup file secretsFortiOS configuration backup files are encrypted with a hard-coded cryptographic key, so anyone who obtains a backup can decrypt the sensitive data i…KEVEPSS 5.8%analysed

Source: NIST National Vulnerability Database (record CVE-2018-12526), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.