← All CVEs

CVE-2014-6436

critical · 9.8

Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.

9.8
CVSS
42.1%
EPSS (exploit prob.)
99th
EPSS percentile
2018-01-12
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-287

Affected products

VendorProductAffected versions
aztechadsl_dsl5018en_(1t1r)_firmwareall versions
aztechadsl_dsl5018en_(1t1r)all versions
aztechdsl705e_firmwareall versions
aztechdsl705eall versions
aztechdsl705eu_firmwareall versions
aztechdsl705euall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-6436