CVE-2018-3881: Focalscope
Critical severity, CVSS 9.4. EPSS: 1.2% chance of exploitation in the next 30 days.
An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticated attacker could submit a specially crafted web request to FocalScope's server that could cause an XXE, and potentially result in data compromise.
Affected products
- Focalscope Focalscope: version 2416 only
Published 2018-08-01. Last modified 2026-06-17.