AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-18638

HIGH · CVSS 8.1 EPSS 2.83%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-10-24 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-18638
Severity
HIGH
CVSS
8.1
EPSS
2.83%

Original NVD Description

A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execute arbitrary commands via shell metacharacters in the ntp field within JSON data to the /robot/initialize endpoint.