CVE-2009-5156

CRITICAL EXPLOITED

ASMAX AR-804gu 66.34.1 - OS Command Injection via cgi-bin/script Query String

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2009-5156 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

An issue was discovered on ASMAX AR-804gu 66.34.1 devices. There is Command Injection via the cgi-bin/script query string.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://www.securityfocus.com/bid/35153
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.securityfocus.com/archive/1/503946

Scores

CVSS v3 9.8
EPSS 0.1092
EPSS Percentile 95.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2019-06-13
CWE
CWE-77
Status published
Products (1)
veracomp/asmax_ar-804gu_firmware 66.34.1
Published Jun 11, 2019
Tracked Since Feb 18, 2026