CVE-2018-9245: Ericssonlg Ipecs Nms

Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.

The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.

Affected products

Published 2018-04-22. Last modified 2026-06-17.