CVE-2018-15555: Actiontec WEB6000Q Firmware

Critical severity, CVSS 9.8. EPSS: 3% chance of exploitation in the next 30 days.

On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and password "admin" by using the enabled onboard UART headers.

Affected products

  • Actiontec WEB6000Q Firmware: version 1.1.02.22 only

Published 2019-06-28. Last modified 2026-06-17.