HIGH · 10.0

CVE-2015-2797

Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0.2.0 and earlier allows remote attackers to execut...

Vulnerability Description

Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the redirect parameter to cgi-bin/login.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
AirtiesAir Firmware<= 1.0.2.0
AirtiesAir 5021-
AirtiesAir 5341-
AirtiesAir 5342-
AirtiesAir 5343-
AirtiesAir 5442-
AirtiesAir 5443-
AirtiesAir 5444Tt-
AirtiesAir 5453-
AirtiesAir 5650Tt-
AirtiesAir 5750-
AirtiesAir 5760-
AirtiesAir 6372-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-2797?

CVE-2015-2797 is a vulnerability with a CVSS score of 10.0 (HIGH). Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0.2.0 and earlier allows remote attackers to execut...

How severe is CVE-2015-2797?

CVE-2015-2797 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-2797?

Check the references section above for vendor advisories and patch information. Affected products include: Airties Air Firmware, Airties Air 5021, Airties Air 5341, Airties Air 5342, Airties Air 5343.