CVE-2001-0740

3COM OfficeConnect 812 and 840 ADSL Router < 1.1.9 - Denial of Service via Format String Attack

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0740. PoCs published by Sniffer.

AI-analyzed exploit summary This exploit triggers a Denial of Service (DoS) in 3Com OfficeConnect 812/840 ADSL routers by sending a maliciously crafted HTTP request with an overly long string, causing the device to reboot. The PoC includes two modes: a soft reset (HTTP POST to /Forms/adsl_reset) and a hard reset (HTTP GET with a long string).

Description

3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attackers to cause a denial of service via a long string containing a large number of "%s" strings, possibly triggering a format string vulnerability.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Sniffer · cdoshardware
https://www.exploit-db.com/exploits/20847

This exploit triggers a Denial of Service (DoS) in 3Com OfficeConnect 812/840 ADSL routers by sending a maliciously crafted HTTP request with an overly long string, causing the device to reboot. The PoC includes two modes: a soft reset (HTTP POST to /Forms/adsl_reset) and a hard reset (HTTP GET with a long string).

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: 3Com OfficeConnect 812/840 ADSL Router (firmware unspecified)
No auth needed
Prerequisites: Network access to the router's HTTP interface (port 80)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=100137290421828&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6573
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-05/0115.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=100119572524232&w=2
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2721

Scores

EPSS 0.0405
EPSS Percentile 89.4%

Details

Status published
Products (2)
3com/3c840-us < 1.1.9
3com/3cp4144 < 1.1.9
Published Oct 18, 2001
Tracked Since Feb 18, 2026