CVE-2014-1982

Alliedtelesis Img646bd Firmware - Authentication Bypass

Title source: rule
STIX 2.1

Description

The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary commands via a direct request to cli.html.

Exploits (1)

exploitdb WRITEUP
by Groundworks Technologies · textwebappshardware
https://www.exploit-db.com/exploits/32545

References (2)

Core 2
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/32545
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Mar/340

Scores

EPSS 0.1047
EPSS Percentile 93.3%

Details

CWE
CWE-287 CWE-78
Status published
Products (8)
alliedtelesis/at-rg634a
alliedtelesis/at-rg634a_firmware 3.3\+
alliedtelesis/img616lh
alliedtelesis/img616lh_firmware \+2.4
alliedtelesis/img624a
alliedtelesis/img624a_firmware 3.5
alliedtelesis/img646bd
alliedtelesis/img646bd_firmware 3.5
Published Mar 31, 2014
Tracked Since Feb 18, 2026