8.1
CVSSv3

CVE-2014-8886

Published: 08/01/2016 Updated: 09/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

AVM FRITZ!OS prior to 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote malicious users to create symlinks or overwrite critical files, and consequently execute arbitrary code, via a crafted firmware image.

Vulnerable Product Search on Vulmon Subscribe to Product

avm fritz\\! os

Exploits

The firmware upgrade process of the FRITZ!Box 7490 is flawed Specially crafted firmware images can overwrite critical files Arbitrary code can get executed if an attempt is made to install such a manipulated firmware Versions prior to 630 are affected ...