CVE-2010-0962
Apple AirPort Express/AirPort Extreme/Time Capsule <7.5 - RCE
Title source: llmDescription
The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56701
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/509867/100/0/threaded
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/38543
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2010/Mar/106
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/509974/100/0/threaded
Scores
EPSS
0.0125
EPSS Percentile
66.2%
Details
CWE
CWE-264
Status
published
Products (3)
apple/airport_express
7.5
apple/airport_extreme
7.5
apple/time_capsule
7.5
Published
Mar 10, 2010
Tracked Since
Feb 18, 2026