CVE-2012-5991

Cisco Wireless LAN Controller Software 7.2.110.0 - Authenticated Denial of Service via web_auth_custom.html Button Click

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-5991.

AI-analyzed exploit summary The exploit demonstrates a chained attack against Cisco Wireless Lan Controller (WLC) 7.2.110.0, combining CSRF, persistent XSS, and a DoS vulnerability. It includes functional HTML/JS code to add an admin user via CSRF and trigger XSS, along with a DoS payload that crashes the WLC via a crafted GET request.

Description

screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote authenticated users to cause a denial of service (device reload) via a certain buttonClicked value in an internal webauth_type request, aka Bug ID CSCud50209.

Exploits (1)

exploitdb WORKING POC
doshardware
https://www.exploit-db.com/exploits/23361

The exploit demonstrates a chained attack against Cisco Wireless Lan Controller (WLC) 7.2.110.0, combining CSRF, persistent XSS, and a DoS vulnerability. It includes functional HTML/JS code to add an admin user via CSRF and trigger XSS, along with a DoS payload that crashes the WLC via a crafted GET request.

Classification
Working Poc 100%
Attack Type
Xss | Dos | Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Cisco Wireless Lan Controller 7.2.110.0
Auth required
Prerequisites: Authenticated session on the target WLC · Victim interaction for CSRF/XSS · Network access to the WLC
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1

Scores

EPSS 0.0552
EPSS Percentile 91.8%

Details

Status published
Products (9)
cisco/2000_wireless_lan_controller
cisco/2100_wireless_lan_controller
cisco/2500_wireless_lan_controller
cisco/4100_wireless_lan_controller
cisco/4400_wireless_lan_controller
cisco/5500_wireless_lan_controller
cisco/7500_wireless_lan_controller
cisco/8500_wireless_lan_controller
cisco/wireless_lan_controller_software 7.2.110.0
Published Dec 19, 2012
Tracked Since Feb 18, 2026