CVE-2014-9727
high · 10AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.
10
CVSS
71.7%
EPSS (exploit prob.)
99th
EPSS percentile
2015-05-29
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| avm | fritz!box | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.exploit-db.com/exploits/33136
- http://www.osvdb.org/103289
- https://www.trustwave.com/Resources/SpiderLabs-Blog/-Honeypot-Alert--Fritz%21Box-%E2%80%93-Remote-Command-Execution-Exploit-Attempt/
- http://www.exploit-db.com/exploits/33136
- http://www.osvdb.org/103289
- https://www.trustwave.com/Resources/SpiderLabs-Blog/-Honeypot-Alert--Fritz%21Box-%E2%80%93-Remote-Command-Execution-Exploit-Attempt/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-9727