56292Third-party advisory
http://secunia.com/advisories/56292 CVE-2014-0659
SerComm Device - Remote Code Execution (Metasploit)
Record summary
CVE-2014-0659 has a selected CVSS score of 10.0; EIP currently links 3 catalogued exploits.
Description
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBSerComm Device - Remote Code Execution (Metasploit)ExploitDB exploitby MetasploitNot analyzed1 file
MetasploitSerComm Network Device Backdoor DetectionMetasploit auxiliary PoCby Eloi Vanderbeken <eloi.vanderbeken@gmail.com> +1 moreNot analyzed1 file
MetasploitSerComm Device Remote Code ExecutionMetasploit exploitby Eloi Vanderbeken <eloi.vanderbeken@gmail.com> +1 moreNot analyzed1 file
References
920140110 Undocumented Test Interface in Cisco Small Business DevicesVendor advisory
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140110-sbd tools.cisco.comConfirmation
http://tools.cisco.com/security/center/viewAlert.x?alertId=32381 64776vdb entry
http://www.securityfocus.com/bid/64776 1029579vdb entry
http://www.securitytracker.com/id/1029579 1029580vdb entry
http://www.securitytracker.com/id/1029580 cisco-small-cve20140659-priv-esc(90233)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/90233 github.com
https://github.com/elvanderb/TCP-32764 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-0659