PT-2017-12123 · Cisco · Cisco Ddr2201V1+1
Published
2017-07-24
·
Updated
2019-10-03
·
CVE-2017-11588
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco DDR2200 ADSL2+ Residential Gateway version V00.00.03.45.4E
Cisco DDR2201v1 ADSL2+ Residential Gateway version V00.00.03.28.3
Description
The issue allows for remote command execution via shell metacharacters in the
pingAddr parameter to the "waitPingqry.cgi" URI. The command output is visible at "/PingMsg.cmd".Recommendations
For Cisco DDR2200 ADSL2+ Residential Gateway version V00.00.03.45.4E, avoid using the
pingAddr parameter in the "waitPingqry.cgi" URI until the issue is resolved.
For Cisco DDR2201v1 ADSL2+ Residential Gateway version V00.00.03.28.3, restrict access to the "waitPingqry.cgi" URI to minimize the risk of exploitation.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ddr2200
Cisco Ddr2201V1