CVE-2018-0284: Cisco Meraki Mr 24 Firmware
Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.
A vulnerability in the local status page functionality of the Cisco Meraki MR, MS, MX, Z1, and Z3 product lines could allow an authenticated, remote attacker to modify device configuration files. The vulnerability occurs when handling requests to the local status page. An exploit could allow the attacker to establish an interactive session to the device with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device that is being exploited.
Affected products
- Cisco Meraki Mr 24 Firmware: before 24.13 (fixed in 24.13)
- Cisco Meraki Mr 25 Firmware: before 25.11 (fixed in 25.11)
- Cisco Meraki Ms 10 Firmware: before 10.20 (fixed in 10.20)
- Cisco Meraki Ms 9 Firmware: before 9.37 (fixed in 9.37)
- Cisco Meraki Mx 13 Firmware: before 13.32 (fixed in 13.32)
- Cisco Meraki Mx 14 Firmware: before 14.25 (fixed in 14.25)
- Cisco Meraki Mx 15 Firmware: before 15.7 (fixed in 15.7)
Published 2018-11-08. Last modified 2026-06-17.