peter bassill · operator
$ cve CVE-2008-4050 JSON

CVE-2008-4050 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 6.7% (pctl 94)

Patch early

A public exploit exists.

Description

A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and read arbitrary registry values via the RegistryValue method, and (2) read arbitrary files via the GetTextFile method.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS6.75% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2008-09-11
Last modified2026-06-16

Affected (1)

VendorProduct
friendly technologiesfriendly pppoe client

Public exploits

SourceTitleDate
exploit-dbFriendly Technologies - Read/Write Registry/Read Files2008-08-30

References

→ the Explorer  ·  watch your stack  ·  NVD