CVE-2018-11681: Lutron Homeworks Qs Firmware

Critical severity, CVSS 9.8. EPSS: 4.2% chance of exploitation in the next 30 days.

Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a vulnerability because what can be done through the ports revolve around controlling lighting, not code execution. A certain set of commands are listed, which bear some similarity to code, but they are not arbitrary and do not allow admin-level control of a machine

Affected products

  • Lutron Homeworks Qs Firmware: affected versions not specified
  • Lutron Radiora 2 Firmware: affected versions not specified
  • Lutron Stanza Firmware: affected versions not specified

Published 2018-06-02. Last modified 2026-06-17.