Critical severity9.8NVD Advisory· Published May 30, 2018· Updated Jun 17, 2026
CVE-2018-11482
CVE-2018-11482
Description
/usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 password.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:o:tp-link:ipc_tl-ipc223\(p\)-6_firmware:*:*:*:*:*:*:*:*Range: <1.0.21
- cpe:2.3:o:tp-link:tl-ipc325\(kp\)_firmware:*:*:*:*:*:*:*:*Range: <1.0.21
Patches
Vulnerability mechanics
References
2- www.us-cert.gov/ncas/bulletins/SB18-155nvdThird Party Advisory
- github.com/yough3rt/IOT-pwn-for-fun/blob/master/TP-LINK-login-Escalation-of-PrivilegesnvdBroken Link
News mentions
0No linked articles in our index yet.