CVE-2015-2797 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 77.8% (pctl 100)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the redirect parameter to cgi-bin/login.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 77.84% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2015-06-19 |
| Last modified | 2026-06-17 |
Affected (13)
| Vendor | Product |
|---|---|
| airties | air 5021 |
| airties | air 5341 |
| airties | air 5342 |
| airties | air 5343 |
| airties | air 5442 |
| airties | air 5443 |
| airties | air 5444tt |
| airties | air 5453 |
| airties | air 5650tt |
| airties | air 5750 |
| airties | air 5760 |
| airties | air 6372 |
| airties | air firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Airties - login-cgi Buffer Overflow (Metasploit) | 2015-06-01 |
| exploit-db | Airties Air5650TT - Remote Stack Overflow | 2015-03-31 |
References
- http://osvdb.org/show/osvdb/120335
- http://www.bmicrosystems.com/blog/exploiting-the-airties-air-series/
- http://www.securityfocus.com/bid/75355
- https://www.exploit-db.com/exploits/36577/
- https://www.exploit-db.com/exploits/37170/
- http://osvdb.org/show/osvdb/120335
- http://www.bmicrosystems.com/blog/exploiting-the-airties-air-series/
- http://www.securityfocus.com/bid/75355
- https://www.exploit-db.com/exploits/36577/
- https://www.exploit-db.com/exploits/37170/
→ the Explorer · watch your stack · NVD