CVE-2018-8819: Carrier Automatedlogic Webctrl

High severity, CVSS 7.5. EPSS: 3% chance of exploitation in the next 30 days.

An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated attacker could enter malicious input to WebCTRL and a weakly configured XML parser will allow the application to disclose full file contents from the underlying web server OS via the "X-Wap-Profile" HTTP header.

Affected products

  • Carrier Automatedlogic Webctrl: version 6.0 only; version 6.1 only; version 6.5 only

Published 2018-06-14. Last modified 2026-06-17.