CVE-2018-20385: Castlenet CBV38Z4EC Firmware
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
CastleNet CBV38Z4EC 125.553mp1.39219mp1.899.007, CBV38Z4ECNIT 125.553mp1.39219mp1.899.005ITT, CBW383G4J 37.556mp5.008, and CBW38G4J 37.553mp1.008 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.
Affected products
- Castlenet CBV38Z4EC Firmware: version 25.553mp1.39219mp1.899.007 only
- Castlenet CBV38Z4ECNIT Firmware: version 125.553mp1.39219mp1.899.005itt only
- Castlenet CBW383G4J Firmware: version 37.556mp5.008 only
- Castlenet CBW38G4J Firmware: version 37.553mp1.008 only
Published 2018-12-23. Last modified 2026-06-17.