Multiple Cisco Wireless Residential Gateway Products Remote Code Execution Vulnerability
BID:68673
Info
Multiple Cisco Wireless Residential Gateway Products Remote Code Execution Vulnerability
| Bugtraq ID: | 68673 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-3306 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2014 12:00AM |
| Updated: | Jul 16 2014 12:00AM |
| Credit: | Chris Watts of Tech Analysis |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple Cisco Wireless Residential Gateway Products Remote Code Execution Vulnerability
Multiple Cisco Wireless Residential Gateway products are prone to a remote code-execution vulnerability.
Attackers can exploit this issue to inject arbitrary commands and execute arbitrary code with elevated privileges. Failed exploit attempts will crash the web server, denying service to legitimate users.
This issue is being tracked by Cisco bug ID CSCup40808.
Multiple Cisco Wireless Residential Gateway products are prone to a remote code-execution vulnerability.
Attackers can exploit this issue to inject arbitrary commands and execute arbitrary code with elevated privileges. Failed exploit attempts will crash the web server, denying service to legitimate users.
This issue is being tracked by Cisco bug ID CSCup40808.
Exploit / POC
Multiple Cisco Wireless Residential Gateway Products Remote Code Execution Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Multiple Cisco Wireless Residential Gateway Products Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Cisco Wireless Residential Gateway Products Remote Code Execution Vulnerability
References:
References:
- Cisco Homepage (Cisco)