CVE-2017-9807
9.8
CRITICAL · CVSS 3.0 · EPSS 4.9% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of "plugin/controllers/models/config.py" performs an eval() call on the contents of the "key" HTTP GET parameter. This allows an unauthenticated remote attacker to execute arbitrary Python code or OS commands via api/saveconfig.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.92% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-06-22 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| openwebif project | openwebif |
References
- http://www.openwall.com/lists/oss-security/2017/10/02/4
- http://www.securityfocus.com/bid/99232
- https://census-labs.com/news/2017/10/02/e2openplugin-openwebif-saveconfig-remote-code-execution/
- https://github.com/E2OpenPlugins/e2openplugin-OpenWebif/issues/620
- http://www.openwall.com/lists/oss-security/2017/10/02/4
- http://www.securityfocus.com/bid/99232
- https://census-labs.com/news/2017/10/02/e2openplugin-openwebif-saveconfig-remote-code-execution/
- https://github.com/E2OpenPlugins/e2openplugin-OpenWebif/issues/620
→ the Explorer · watch your stack · NVD