← Vulnerability feed

Vulnerability record · CVE-2018-20393 · published 23 December 2018

CVE-2018-20393: Technicolor cga0111 firmware vulnerability

Technicolor · Cga0111 Firmware

Technicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU, CWA0101 CWA0101E-A23E-c7000r5712-170315-SKC, DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a, TC7110.AR STD3.38.03, TC7110.B STC8.62.02, TC7110.D STDB.79.02, TC7200.d1I TC7200.d1IE-N23E-c7000r5712-170406-HAT, and TC7200.TH2v2 SC05.00.22 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

9.8 CVSS 3.0 Critical EPSS 1.6% · top 25.2%
9.8CVSS 3.0 base score, v2 5.0
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
8Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Technicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU, CWA0101 CWA0101E-A23E-c7000r5712-170315-SKC, DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a, TC7110.AR STD3.38.03, TC7110.B STC8.62.02, TC7110.D STDB.79.02, TC7200.d1I TC7200.d1IE-N23E-c7000r5712-170406-HAT, and TC7200.TH2v2 SC05.00.22 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-20393 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-20444Technicolor cga0111 firmware insufficiently protected credentials vulnerabilityTechnicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.441…EPSS 1.3%9.8CVE-2018-20439Technicolor dpc3928sl firmware insufficiently protected credentials vulnerabilityTechnicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.…EPSS 1.3%9.8CVE-2018-20438Technicolor tc7110.ar firmware insufficiently protected credentials vulnerabilityTechnicolor TC7110.AR STD3.38.03 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and is…EPSS 1.4%9.8CVE-2018-20442Technicolor tc7110.b firmware insufficiently protected credentials vulnerabilityTechnicolor TC7110.B STC8.62.02 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and iso…EPSS 1.4%9.1CVE-2017-5135Technicolor dpc3928sl firmware vulnerabilityCertain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. The Technicolor (formerly Cisc…EPSS 18%4.7CVE-2018-20379Technicolor dpc3928sl firmware cross-site scripting vulnerabilityTechnicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-160428a devices allow XSS via a Cross Protocol Injection attack with setSSID of 1.3.6.1.4.1.44…EPSS 0.57%

Source: NIST National Vulnerability Database (record CVE-2018-20393), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.