PT-2017-12123 · Cisco · Cisco Ddr2201V1+1

Published

2017-07-24

·

Updated

2019-10-03

·

CVE-2017-11588

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco DDR2200 ADSL2+ Residential Gateway version V00.00.03.45.4E Cisco DDR2201v1 ADSL2+ Residential Gateway version V00.00.03.28.3
Description The issue allows for remote command execution via shell metacharacters in the pingAddr parameter to the "waitPingqry.cgi" URI. The command output is visible at "/PingMsg.cmd".
Recommendations For Cisco DDR2200 ADSL2+ Residential Gateway version V00.00.03.45.4E, avoid using the pingAddr parameter in the "waitPingqry.cgi" URI until the issue is resolved. For Cisco DDR2201v1 ADSL2+ Residential Gateway version V00.00.03.28.3, restrict access to the "waitPingqry.cgi" URI to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11588

Affected Products

Cisco Ddr2200
Cisco Ddr2201V1