CVE-2018-20387: Bnmux BCW700J Firmware

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Bnmux BCW700J 5.20.7, BCW710J 5.30.6a, and BCW710J2 5.30.16 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

Affected products

  • Bnmux BCW700J Firmware: version 5.20.7 only
  • Bnmux BCW710J2 Firmware: version 5.30.16 only
  • Bnmux BCW710J Firmware: version 5.30.6a only

Published 2018-12-23. Last modified 2026-06-17.