CVE-2018-15485: Kone Group Controller Firmware

Critical severity, CVSS 9.1. EPSS: 2.5% chance of exploitation in the next 30 days.

An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. FTP does not require authentication or authorization, aka KONE-03.

Affected products

  • Kone Group Controller Firmware: before 4.6.5 (fixed in 4.6.5)

Published 2018-09-07. Last modified 2026-06-17.