Remote Code Execution Vulnerability in AirTies DSL Modems

Remote Code Execution Vulnerability in AirTies DSL Modems

CVE-2015-2797 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the redirect parameter to cgi-bin/login.

Learn more about our Web Application Penetration Testing UK.