← All CVEs

CVE-2014-0659

high · 10

The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.

10
CVSS
73.8%
EPSS (exploit prob.)
99th
EPSS percentile
2014-01-12
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
ciscorvs4000_firmware<= 2.0.3.2
ciscorvs4000_firmware1.3.2.0
ciscorvs4000_firmware1.3.3.5
ciscorvs4000_firmware2.0.0.3
ciscorvs4000_firmware2.0.2.7
ciscorvs4000all versions
ciscowrvs4400n_firmware1.1.03
ciscowrvs4400n_firmware1.1.13
ciscowrvs4400n_firmware2.0.1.3
ciscowrvs4400n_firmware2.0.2.1
ciscowrvs4400nall versions
ciscowap4410n_firmware<= 2.0.6.1
ciscowap4410n_firmware2.0.2.1
ciscowap4410n_firmware2.0.3.3
ciscowap4410n_firmware2.0.4.2
ciscowap4410nall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-0659