← Back to browse · API

CVE-2018-4018

Severity
CRITICAL
CVSS
10.0
EPSS
0.02332
Risk score
40.82
CISA KEV
No
PoC
No
Published
2019-05-13
Modified
2024-08-05
First seen
2026-08-07
Aliases
EUVD-2018-15804, GHSA-V2PP-7FP2-VFJG
Products
n/a:Novatek Anker Roav A1 Dashcam RoavA1SWV1.9
Sources
euvd EUVD-2018-15804

Description

An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware, running on Anker Roav A1 Dashcam version RoavA1SWV1.9. The HTTP server allows for arbitrary firmware binaries to be uploaded which will be flashed upon next reboot. An attacker can send an HTTP PUT request or upgrade firmware request to trigger this vulnerability.

References