CVE-2014-6436 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 42.1% (pctl 99)
Patch early
A public exploit exists.
Description
Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 42.13% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-01-12 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| aztech | adsl dsl5018en \(1t1r\) |
| aztech | adsl dsl5018en \(1t1r\) firmware |
| aztech | dsl705e |
| aztech | dsl705e firmware |
| aztech | dsl705eu |
| aztech | dsl705eu firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Aztech Modem Routers - Session Hijacking | 2014-09-15 |
References
- http://packetstormsecurity.com/files/128254/Aztech-DSL5018EN-DSL705E-DSL705EU-DoS-Broken-Session-Management.html
- http://www.securityfocus.com/archive/1/533489/100/0/threaded
- http://www.securityfocus.com/bid/69811
- http://packetstormsecurity.com/files/128254/Aztech-DSL5018EN-DSL705E-DSL705EU-DoS-Broken-Session-Management.html
- http://www.securityfocus.com/archive/1/533489/100/0/threaded
- http://www.securityfocus.com/bid/69811
→ the Explorer · watch your stack · NVD