CVE-2012-0902

AirTies Air 4450 1.1.2.18 - Denial of Service via Direct Request to cgi-bin/loader

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-0902. PoCs published by rigan.

AI-analyzed exploit summary This Perl script exploits an unauthorized remote reboot vulnerability in AirTies Air-4450 routers by sending repeated GET requests to the `/cgi-bin/loader` endpoint, causing a denial of service (DoS). The exploit targets a specific firmware version and requires no authentication.

Description

AirTies Air 4450 1.1.2.18 allows remote attackers to cause a denial of service (reboot) via a direct request to cgi-bin/loader.

Exploits (1)

exploitdb WORKING POC
by rigan · perldoshardware
https://www.exploit-db.com/exploits/18336

This Perl script exploits an unauthorized remote reboot vulnerability in AirTies Air-4450 routers by sending repeated GET requests to the `/cgi-bin/loader` endpoint, causing a denial of service (DoS). The exploit targets a specific firmware version and requires no authentication.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: AirTies Air-4450 firmware AirTies_Air4450_RU_FW_1.1.2.18.bin
No auth needed
Prerequisites: Network access to the target device · Target device must be running vulnerable firmware
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51320
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18336
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72200

Scores

EPSS 0.0587
EPSS Percentile 90.8%

Details

Status published
Products (1)
airties/air_4450 1.1.2.18
Published Jan 20, 2012
Tracked Since Feb 18, 2026