7.8
CVSSv3

CVE-2014-8872

Published: 29/08/2017 Updated: 09/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50.

Vulnerable Product Search on Vulmon Subscribe to Product

avm fritz\\!box_6810_lte_firmware -

avm fritz\\!box_6840_lte_firmware -

Exploits

The signature check of FRITZ!Box firmware images is flawed Malicious code can be injected into firmware images without breaking the RSA signature The code will be executed either if a manipulated firmware image is uploaded by the victim or if the victim confirms an update on the webinterface during a MITM attack ...