Vulnerability record · CVE-2018-19524 · published 21 March 2019
CVE-2018-19524: Skyworth GPON terminal Web_passwd stack overflow allows unauthenticated RCE
Skyworthdigital · Dt740 Firmware
The Web_passwd function on Shenzhen Skyworth DT741, DT721-cb and DT741-cb GPON/IPTV terminals fails to validate password length, so an oversized password overflows the stack and corrupts registers S0-S4 and T4-T7. This lets a remote, unauthenticated attacker either crash the device or execute arbitrary code on it.
Description
An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 devices. A long password to the Web_passwd function allows remote attackers to cause a denial of service (segmentation fault) or achieve unauthenticated remote code execution because of control of registers S0 through S4 and T4 through T7.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a CVSS of 9.8 and public exploit code makes this critical for any exposed device.
What it is
The Web_passwd function on Shenzhen Skyworth DT741, DT721-cb and DT741-cb GPON/IPTV terminals fails to validate password length, so an oversized password overflows the stack and corrupts registers S0-S4 and T4-T7. This lets a remote, unauthenticated attacker either crash the device or execute arbitrary code on it.
Impact
An attacker gains unauthenticated remote code execution on the affected terminal, or can at minimum cause a denial of service via segmentation fault. Full compromise of the device gives control over the gateway and any traffic or credentials it handles.
Attack surface
Reachable over the network through the web interface's Web_passwd function; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and description confirm no authentication and no user interaction are required.
Exploitation
Public exploit code exists (Exploit-DB 46358 and Packet Storm/Full Disclosure postings tagged Exploit), and EPSS is high at roughly 0.51 (98.9th percentile), though the CVE is not listed in CISA KEV.
What to do
- Apply vendor firmware updates for DT741, DT721-cb and DT741-cb if Skyworth has released them; the record does not name a fixed version, so confirm with the vendor.
- If no patch exists, isolate the device management/web interface from untrusted networks and restrict access to a trusted management VLAN.
- Disable or block remote access to the device web UI from WAN/ISP-facing interfaces where the deployment allows it.
- Replace end-of-life terminals that no longer receive firmware support.
- Monitor the vendor and ISP for remediation guidance since this is carrier-supplied CPE.
Detection
- Alert on oversized or malformed password parameters sent to the Web_passwd endpoint in web/proxy logs.
- Monitor the device for unexpected reboots, crashes or segmentation faults indicating exploitation attempts.
- Watch for anomalous outbound connections or new listening services from the terminal that suggest code execution.
- Use network monitoring to flag exploit traffic matching public PoCs against the device web interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-19524 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-19524), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.