CVE-2018-14067: Greenpacket Dv-360 Firmware

Critical severity, CVSS 9.8. EPSS: 7.3% chance of exploitation in the next 30 days.

Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command execution, via a crafted payload to the HTTPS port, because lighttpd listens on all network interfaces (including the external Internet) by default. NOTE: this may overlap CVE-2017-9980.

Affected products

  • Greenpacket Dv-360 Firmware: version 2.10.14-g1.0.6.1 only

Published 2020-12-31. Last modified 2026-06-17.