S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-16668 Scanner

CVE-2018-16668 scanner - Information Disclosure vulnerability in CIRCONTROL CirCarLife

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-16668
5.3
CVSS

An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

CIRCONTROL CirCarLife is a software designed for electric vehicle charging management, allowing the user to monitor charging point usage, manage charging schedules, and view consumption reports. It is primarily used in commercial settings such as parking lots, businesses, and public charging stations. 

However, this software has been found to contain a critical vulnerability, identified as CVE-2018-16668. This vulnerability allows for the disclosure of internal installation paths due to the lack of authentication for the /html/repository function. 

The exploitation of this vulnerability can lead to sensitive information being disclosed, which can be used by malicious actors to access other areas of the software and gather additional information. This vulnerability can also lead to potential breaches of customer and user data, compromising privacy and security. 

By utilizing the pro features of the s4e.io platform, readers of this article can quickly and easily learn about vulnerabilities in their digital assets, protecting against potentially damaging attacks. With the ever-increasing threat of cyber attacks, it is crucial that software vulnerabilities are identified and addressed promptly to ensure the continued security and safeguarding of private information.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Upgrade to a patched version of CIRCONTROL CirCarLife software.
  • Ensure that the software is configured to require authentication for all functions and access points.
  • Use strong, unique passwords for all user accounts and regularly update them.
  • Implement regular security audits and penetration testing to identify vulnerabilities and ensure that the software remains secure.
  • Monitor network traffic and user activity for any signs of unauthorized access or suspicious behavior.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-16668 scanner - Information Disclosure vulnerability in CIRCONTROL CirCarLife | S4E