CVE-2018-20512: Cdatatec Epon CPE-Wifi Devices Firmware

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.

Affected products

  • Cdatatec Epon CPE-Wifi Devices Firmware: version 2.0.4-x000 only

Published 2019-01-03. Last modified 2026-06-17.