9.3
CVSSv2

CVE-2009-1807

Published: 28/05/2009 Updated: 09/06/2009
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and previous versions allows remote malicious users to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009.

Vulnerable Product Search on Vulmon Subscribe to Product

baofeng storm 2.7.9_8

baofeng storm 2.8

baofeng storm 2.9

baofeng storm

baofeng storm 2.7.9_10

Exploits

# # BaoFeng (configdll) ActiveX Remote Code Execution Exploit # Exploit made by etirah # Download: wwwbaofengcom # # Problem DLL : configdll # Problem Func : SetAttributeValue(param1,param2,param3) # Problem Param : param1 # # References: # 1 forumeviloctalcom/viewthreadphp?tid=35051 # 2 wwwmilw0rmcom/ex ...