peter bassill · operator
$ cve CVE-2009-1807 JSON

CVE-2009-1807 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 7.5% (pctl 94)

Patch early

A public exploit exists.

Description

Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS7.53% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2009-05-28
Last modified2026-06-16

Affected (1)

VendorProduct
baofengstorm

Public exploits

SourceTitleDate
exploit-dbBaoFeng - 'config.dll' ActiveX Remote Code Execution2009-05-21

References

→ the Explorer  ·  watch your stack  ·  NVD