CVE-2009-0695
Wyse Device Manager <4.7.x - RCE
Title source: llmDescription
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.
Exploits (3)
metasploit
WORKING POC
EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/wyse/hagent_untrusted_hsdata.rb
References (5)
Scores
EPSS
0.6423
EPSS Percentile
98.4%
Classification
CWE
CWE-287
Status
draft
Affected Products (3)
dell/wyse_device_manager
dell/wyse_device_manager
dell/wyse_device_manager
Timeline
Published
Jun 19, 2012
Tracked Since
Feb 18, 2026