PoC Index

CVE-2014-6436

HIGH 10.0EPSS 42.1%

Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
42.13% chance of exploitation in the next 30 days, 99th percentile
Published
2018-01-12
Updated
2024-08-06

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related