CVE-2018-20218 | Teracue ENC-400 up to 2.56 Login Form /usr/share/www/check.lp password command injection (EDB-46451)
A vulnerability classified as critical was found in Teracue ENC-400 up to 2.56. Affected by this vulnerability is an unknown functionality of the file /usr/share/www/check.lp of the component Login Form. The manipulation of the argument password as part of Parameter leads to command injection.
This vulnerability is known as CVE-2018-20218. The attack can be launched remotely. Furthermore, there is an exploit available.