CVE-2014-9727

EXPLOITED IN THE WILD

AVM Fritz!Box - Remote Command Execution via var:lang Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2014-9727 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 2 public exploits from researchers including 0x4148, Unknown, including a Metasploit module exploits/linux/http/fritzbox_echo_exec.

AI-analyzed exploit summary This exploit leverages an unauthenticated remote command execution vulnerability in Fritz!Box routers by injecting shell commands via the 'var:lang' parameter in a crafted URL. The PoC demonstrates reading the VoIP configuration file, confirming arbitrary command execution.

Description

AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.

Exploits (2)

exploitdb WORKING POC
by 0x4148 · textwebappshardware
https://www.exploit-db.com/exploits/33136

This exploit leverages an unauthenticated remote command execution vulnerability in Fritz!Box routers by injecting shell commands via the 'var:lang' parameter in a crafted URL. The PoC demonstrates reading the VoIP configuration file, confirming arbitrary command execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Fritz!Box (multiple versions, likely pre-2014)
No auth needed
Prerequisites: Network access to the Fritz!Box web interface · Target device must be vulnerable to CVE-2014-9727
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Unknown · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/fritzbox_echo_exec.rb

This Metasploit module exploits an unauthenticated OS command injection vulnerability in various Fritz!Box devices via the `/cgi-bin/webcm` endpoint. It uses the `var:lang` parameter to inject commands and achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Fritz!Box (multiple models including 7270, 7570, 7490, etc.)
No auth needed
Prerequisites: Network access to the target device · Vulnerable Fritz!Box firmware
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/33136
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/103289

Scores

EPSS 0.7164
EPSS Percentile 99.3%

Details

VulnCheck KEV 2020-05-07
InTheWild.io 2023-02-15
CWE
CWE-78
Status published
Products (1)
avm/fritz\!box
Published May 29, 2015
Tracked Since Feb 18, 2026