PoC Index

CVE-2015-6023

HIGH 7.5EPSS 11.0%

ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intended access restrictions via a direct request. NOTE: this issue can be combined with CVE-2015-6024 to execute arbitrary commands.

CVSS v3.0
7.3 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
10.98% chance of exploitation in the next 30 days, 96th percentile
Published
2017-02-09
Updated
2024-08-06

Proof-of-concept exploits (2)

ExploitDB entries (1)

References

Related