CVE-2018-13858: Trivum c4 Professional Firmware
Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.
MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional allows unauthorized remote attackers to reboot or execute other functions via the "/xml/system/control.xml" URL, using the GET request "?action=reboot" for example.
Affected products
- Trivum c4 Professional Firmware: version 8.76 only
Published 2018-07-17. Last modified 2026-06-17.