CVE-2009-3962 EXPLOIT
7.8
HIGH · CVSS 2.0 · EPSS 3% (pctl 87)
Patch early
A public exploit exists.
Description
The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.29.52 allows remote attackers to cause a denial of service (reboot) via a %0d%0a sequence in the page parameter to the xslt program on TCP port 50001, a related issue to CVE-2006-4523.
Scoring
| CVSS | 7.8 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
| EPSS | 3.02% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-11-17 |
| Last modified | 2026-06-16 |
Affected (6)
| Vendor | Product |
|---|---|
| 2wire | 1700hg |
| 2wire | 1701hg |
| 2wire | 1800hw |
| 2wire | 2071 |
| 2wire | 2700hg |
| 2wire | 2701hg-t |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | 2WIRE Modems/Routers - 'CRLF' Denial of Service | 2006-08-22 |
References
- http://webvuln.com/advisories/2wire.remote.denial.of.service.txt
- http://www.securityfocus.com/archive/1/507587/100/0/threaded
- http://www.securitytracker.com/id?1023116
- http://www.vupen.com/english/advisories/2009/3110
- http://webvuln.com/advisories/2wire.remote.denial.of.service.txt
- http://www.securityfocus.com/archive/1/507587/100/0/threaded
- http://www.securitytracker.com/id?1023116
- http://www.vupen.com/english/advisories/2009/3110
→ the Explorer · watch your stack · NVD