packetstormsecurity.com
http://packetstormsecurity.com/files/128254/Aztech-DSL5018EN-DSL705E-DSL705EU-DoS-Broken-Session-Management.html CVE-2014-6436
CRITICAL
Aztech Modem Routers - Session Hijacking
Record summary
CVE-2014-6436 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAztech Modem Routers - Session HijackingExploitDB exploitby Eric FajardoNot analyzed1 file
References
420140919 Re: Multiple Vulnerabilities with Aztech Modem Routersmailing list
http://www.securityfocus.com/archive/1/533489/100/0/threaded 69811vdb entry
http://www.securityfocus.com/bid/69811 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-6436