A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9 could allow an authenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. This vulnerability is due to insufficient input validation on user-controlled input in an HTTP request to the targeted device. An attacker in possession of router login credentials could exploit this vulnerability by sending a crafted HTTP request to an affected system.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Sierrawireless
Subscribe
|
Es440
Subscribe
Es440 Firmware
Subscribe
Es450
Subscribe
Es450 Firmware
Subscribe
Gx400
Subscribe
Gx400 Firmware
Subscribe
Gx440
Subscribe
Gx440 Firmware
Subscribe
Gx450
Subscribe
Gx450 Firmware
Subscribe
Ls300
Subscribe
Ls300 Firmware
Subscribe
Mp70
Subscribe
Mp70 Firmware
Subscribe
Mp70e
Subscribe
Mp70e Firmware
Subscribe
Rv50
Subscribe
Rv50 Firmware
Subscribe
Rv50x
Subscribe
Rv50x Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-6518 | A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9 could allow an authenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. This vulnerability is due to insufficient input validation on user-controlled input in an HTTP request to the targeted device. An attacker in possession of router login credentials could exploit this vulnerability by sending a crafted HTTP request to an affected system. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T19:42:22.419Z
Reserved: 2017-10-05T00:00:00.000Z
Link: CVE-2017-15043
No data.
Status : Modified
Published: 2018-05-04T20:29:00.437
Modified: 2024-11-21T03:13:59.653
Link: CVE-2017-15043
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD