CVE-2014-1635
72Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 67%
from disclosure to weapon0 days
Published on NVDNov 12
1st PoCNov 6
metasploitMay 9
VulnCheck+3984d
exploitation probability
67%top 1% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote attackers to execute arbitrary code via a long string in the jump parameter.
Affected products
n/a · n/apublic PoCs found — 3✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/35184cve_referencewww.exploit-db.com/exploits/35184unverifiedvulncheckvulncheck.com/xdb/f3d43fc6cde3unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/show/osvdb/114345https://labs.integrity.pt/advisories/cve-2014-1635/https://labs.integrity.pt/articles/from-0-day-to-exploit-buffer-overflow-in-belkin-n750-cve-2014-1635/http://www.belkin.com/us/support-article?articleNum=4831http://www.exploit-db.com/exploits/35184http://www.securityfocus.com/bid/70977http://www.securitytracker.com/id/1031210