S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-16671 Scanner

CVE-2018-16671 scanner - Information Disclosure vulnerability in CirCarLife

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-16671
5.3
CVSS

An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

CIRCONTROL CirCarLife is a software used in electric vehicle charging stations that allows drivers to monitor the charging status of their car in real-time. The software can be accessed through a web portal or a mobile application, making it convenient for electric car owners to remotely view their charging progress and receive alerts when their car is fully charged.

However, the CVE-2018-16671 vulnerability was detected in the CirCarLife software, which posed a significant security risk. The lack of authentication for /html/device-id could lead to system software information disclosure. This means that an attacker could gain unauthorized access to sensitive information about the charging station, including location, power output, and even operational protocols. 

When exploited, this vulnerability could potentially allow hackers to hijack the charging station, steal sensitive data or disrupt the charging service. Hackers may also exploit this vulnerability to launch attacks on the network connected to the charging station.

In conclusion, as digital technology continues to advance, so do the risks of cyberattacks. It is essential to stay vigilant and take proactive measures to secure our digital assets. s4e.io provides users with access to pro features that allow them to quickly and easily identify vulnerabilities in their digital assets, which can help prevent potential attacks and mitigate risks. Don't wait until it is too late, take action now to safeguard your digital security.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Update the software to the latest version that patches the vulnerability.
  • Implement strong authentication mechanisms to secure access to the system.
  • Limit access to the charging station to authorized personnel only.
  • Regularly review access logs to monitor any suspicious activity.
  • Keep all connected devices updated with the latest security patches and configurations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-16671 scanner - Information Disclosure vulnerability in CirCarLife | S4E