CVE-2018-17903
CVE-2018-17903 is a critical-severity vulnerability in Sagaradio Saga1-l8b Firmware with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-294.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- CVSS v2: 6.4
- EPSS exploit prediction: 2% (75th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-294
- Affected product: Sagaradio Saga1-l8b Firmware
- Published:
- Last modified:
Description
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery.
Frequently asked questions
- What is CVE-2018-17903?
- SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery.
- How severe is CVE-2018-17903?
- CVE-2018-17903 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability high.
- Is CVE-2018-17903 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (75th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2018-17903?
- CVE-2018-17903 affects Sagaradio Saga1-l8b Firmware. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2018-17903?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2018-17903 published?
- CVE-2018-17903 was published on 2018-10-24 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:o:sagaradio:saga1-l8b_firmware:*:*:*:*:*:*:*:*
More vulnerabilities in Sagaradio Saga1-l8b Firmware
- CVE-2018-17921 — High (CVSS 8.8): SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that may allow an attacker to…
- CVE-2018-17923 — Medium (CVSS 6.9): SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access…
All CVEs affecting Sagaradio Saga1-l8b Firmware →
Other CWE-294 (Authentication Bypass by Capture-replay) vulnerabilities
- CVE-2025-49752 — Critical (CVSS 10.0): Azure Bastion Elevation of Privilege Vulnerability
- CVE-2026-88278 — Critical (CVSS 9.8): GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a…
- CVE-2026-86219 — Critical (CVSS 9.8): Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified…
- CVE-2026-65905 — Critical (CVSS 9.8): Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize…
- CVE-2026-68079 — Critical (CVSS 9.8): In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number…
- CVE-2026-28564 — Critical (CVSS 9.8): Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic…
Browse all CWE-294 (Authentication Bypass by Capture-replay) vulnerabilities →