CVE-2018-15484: Kone Group Controller Firmware
Critical severity, CVSS 9.8. EPSS: 7.7% chance of exploitation in the next 30 days.
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Remote Code Execution is possible through the open HTTP interface by modifying autoexec.bat, aka KONE-01.
Affected products
- Kone Group Controller Firmware: before 4.6.5 (fixed in 4.6.5)
Published 2018-09-07. Last modified 2026-06-17.