{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-01T03:39:47.171","vulnerabilities":[{"cve":{"id":"CVE-2018-16596","sourceIdentifier":"cve@mitre.org","published":"2018-12-17T19:29:00.533","lastModified":"2026-06-17T01:44:31.537","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A stack-based buffer overflow in the LAN UPnP service running on UDP port 1900 of Swisscom Internet-Box (2, Standard, and Plus) prior to v09.04.00 and Internet-Box light prior to v08.05.02 allows remote code execution. No authentication is required to exploit this vulnerability. Sending a simple UDP packet to port 1900 allows an attacker to execute code on a remote device. However, this is only possible if the attacker is inside the LAN. Because of ASLR, the success rate is not 100% and leads instead to a DoS of the UPnP service. The remaining functionality of the Internet Box is not affected. A reboot of the Internet Box is necessary to attempt the exploit again."},{"lang":"es","value":"Un desbordamiento de búfer basado en pila en el servicio LAN UPnP que se ejecuta en el puerto 1900 UDP de Swisscom Internet-Box (2, Standard y Plus) en versiones anteriores a la v09.04.00, e Internet-Box light en versiones anteriores a la v08.05.02 permite la ejecución remota de código. No se requiere autenticación para explotar esta vulnerabilidad. El envío de un simple paquete UDP al puerto UDP 1900 permite que un atacante ejecute código en un dispositivo remoto. Sin embargo, esto solo es posible si el atacante está dentro de la LAN. Debido a ASLR, el porcentaje de éxito no es del 100% y conduce a la denegación de servicio (DoS) del servicio UPnP. Las funcionalidades restantes de Internet Box no se han visto afectadas. Es necesario reiniciar Internet Box para intentar su explotación nuevamente."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:M/Au:N/C:P/I:P/A:P","baseScore":5.4,"accessVector":"ADJACENT_NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":5.5,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:swisscom:internet-box_standard_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"09.04.00","matchCriteriaId":"2C4EA63A-F1F7-4D40-89F8-488CEBA10EDB"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:swisscom:internet-box_2:-:*:*:*:*:*:*:*","matchCriteriaId":"927142EA-D46E-4A31-AAA1-6B1826BB0A85"},{"vulnerable":false,"criteria":"cpe:2.3:h:swisscom:internet-box_standard:-:*:*:*:*:*:*:*","matchCriteriaId":"5EFFDE19-42FB-452F-AB21-6FBE0E9B3441"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:swisscom:internet-box_light_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"08.05.02","matchCriteriaId":"68A16941-3C3D-4F29-A234-51D8026F94DF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:swisscom:internet-box_light:-:*:*:*:*:*:*:*","matchCriteriaId":"8D535048-7F72-438E-BF84-7DB7F9060919"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:swisscom:internet-box_plus_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"09.04.00","matchCriteriaId":"DDD9AC3D-B9EF-43AF-816B-F51502AD62BC"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:swisscom:internet-box_plus:-:*:*:*:*:*:*:*","matchCriteriaId":"39825764-48CD-40BC-9FEA-6847A18B7868"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:swisscom:internet-box_2_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"09.04.00","matchCriteriaId":"46364036-0834-45BF-A888-7B352D9AFFB1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:swisscom:internet-box_2:-:*:*:*:*:*:*:*","matchCriteriaId":"927142EA-D46E-4A31-AAA1-6B1826BB0A85"}]}]}],"references":[{"url":"https://www.swisscom.ch/content/dam/swisscom/de/about/nachhaltigkeit/digitale-schweiz/sicherheit/bug-bounty/files/cve-2018-16596.txt","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://www.swisscom.ch/content/dam/swisscom/de/about/nachhaltigkeit/digitale-schweiz/sicherheit/bug-bounty/files/cve-2018-16596.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}