{"api_version":"1","generated_at":"2026-07-23T08:13:25+00:00","cve":"CVE-2009-1807","urls":{"html":"https://cve.report/CVE-2009-1807","api":"https://cve.report/api/cve/CVE-2009-1807.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-1807","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-1807"},"summary":{"title":"CVE-2009-1807","description":"Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-05-28 20:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2009/1392","name":"http://www.vupen.com/english/advisories/2009/1392","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.cisrt.org/enblog/read.php?245","name":"http://www.cisrt.org/enblog/read.php?245","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Three new 0-day Exploits used in drive-by-download attack in China - C.I.S.R.T. - Chinese Internet Security Response Team (GMT +0800)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-1807","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1807","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"1807","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"baofeng","cpe5":"storm","cpe6":"2.7.9_10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1807","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"baofeng","cpe5":"storm","cpe6":"2.7.9_8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1807","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"baofeng","cpe5":"storm","cpe6":"2.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1807","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"baofeng","cpe5":"storm","cpe6":"2.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1807","vulnerable":"1","versionEndIncluding":"3.09.04.17","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"baofeng","cpe5":"storm","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:27:54.345Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2009-1392","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/1392"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.cisrt.org/enblog/read.php?245"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-05-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-06-09T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2009-1392","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/1392"},{"tags":["x_refsource_MISC"],"url":"http://www.cisrt.org/enblog/read.php?245"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-1807","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2009-1392","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/1392"},{"name":"http://www.cisrt.org/enblog/read.php?245","refsource":"MISC","url":"http://www.cisrt.org/enblog/read.php?245"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-1807","datePublished":"2009-05-28T20:14:00.000Z","dateReserved":"2009-05-28T00:00:00.000Z","dateUpdated":"2024-08-07T05:27:54.345Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-05-28 20:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:baofeng:storm:*:*:*:*:*:*:*:*","versionEndIncluding":"3.09.04.17","matchCriteriaId":"562E2843-2197-4945-8141-DC06F55D6F30"},{"vulnerable":true,"criteria":"cpe:2.3:a:baofeng:storm:2.7.9_8:*:*:*:*:*:*:*","matchCriteriaId":"3F52CD8D-3166-4A06-BB43-B7DEE653FBDB"},{"vulnerable":true,"criteria":"cpe:2.3:a:baofeng:storm:2.7.9_10:*:*:*:*:*:*:*","matchCriteriaId":"BD543322-FB0F-45E0-9E93-347425B470BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:baofeng:storm:2.8:*:*:*:*:*:*:*","matchCriteriaId":"5BF09EE7-F241-4EDE-8266-FD2413C6E1AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:baofeng:storm:2.9:*:*:*:*:*:*:*","matchCriteriaId":"93399125-BFCD-4EEC-B187-3E89A8DB82D2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"1807","Ordinal":"1","Title":"CVE-2009-1807","CVE":"CVE-2009-1807","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"1807","Ordinal":"1","NoteData":"Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009.","Type":"Description","Title":"CVE-2009-1807"},{"CveYear":"2009","CveId":"1807","Ordinal":"2","NoteData":"2009-05-28","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"1807","Ordinal":"3","NoteData":"2009-06-09","Type":"Other","Title":"Modified"}]}}}