Vulnerability Name: | CVE-2014-7269 (CCN-100396) | ||||||||
Assigned: | 2014-09-30 | ||||||||
Published: | 2015-01-27 | ||||||||
Updated: | 2015-02-04 | ||||||||
Summary: | ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers with firmware 3.0.0.4.376.3715 and earlier, RT-N66U routers with firmware 3.0.0.4.376.3715 and earlier, and RT-N56U routers with firmware 3.0.0.4.376.3715 and earlier allow remote authenticated users to execute arbitrary OS commands via unspecified vectors. | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P) 4.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
4.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-78 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-7269 Source: CCN Type: JVN#77792759 Multiple ASUS wireless LAN routers vulnerable to OS command injection Source: JVN Type: Vendor Advisory JVN#77792759 Source: JVNDB Type: Vendor Advisory JVNDB-2015-000011 Source: CCN Type: ASUS Web site Firmware for wireless LAN routers that addressed cross-site request forgery and OS command injection vulnerabilities are available Source: CONFIRM Type: Patch, Vendor Advisory http://www.asus.com/jp/News/PNzPd7vkXtrKWXHR Source: CCN Type: BID-72390 ASUS RT Series Routers CVE-2014-7269 Unspecified Command Injection Vulnerability Source: XF Type: UNKNOWN asus-rt-cve20147269-command-exec(100396) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration 5: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |