CVE-2018-8755: Nucom WR644GACV Firmware

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

NuCom WR644GACV devices before STA006 allow an attacker to download the configuration file without credentials. By downloading this file, an attacker can access the admin password, WPA key, and any config information of the device.

Affected products

  • Nucom WR644GACV Firmware: before sta006 (fixed in sta006)

Published 2018-06-25. Last modified 2026-06-17.