10
CVSSv2

CVE-2014-1982

Published: 31/03/2014 Updated: 31/03/2014
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote malicious users to gain privileges and execute arbitrary commands via a direct request to cli.html.

Vulnerable Product Search on Vulmon Subscribe to Product

alliedtelesis img646bd_firmware 3.5

alliedtelesis img646bd -

alliedtelesis at-rg634a_firmware 3.3\\+

alliedtelesis at-rg634a -

alliedtelesis img624a_firmware 3.5

alliedtelesis img624a -

alliedtelesis img616lh_firmware \\+2.4

alliedtelesis img616lh -

Exploits

*Title:* Allied Telesis AT-RG634A ADSL Broadband router hidden administrative unauthenticated webshell *Vulnerability Information:* - CVE: CVE-2014-1982 - Type of Vulnerability: - CWE-78 : OS Command Injection - CWE-306 : Missing Authentication for Critical Function *Affected products:* - Allied Telesis AT-RG634A ADSL Broadband router (v ...
Allied Telesis AT-RG634A ADSL broadband router has hidden administrative unauthenticated webshell that allows for command injection ...