← Back to CVEs
CVE-2014-8886
N/ADescription
AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote attackers to create symlinks or overwrite critical files, and consequently execute arbitrary code, via a crafted firmware image.
CVE Details
CVSS v3.1 ScoreN/A
Published1/8/2016
Last Modified4/12/2025
Sourcenvd
Honeypot Sightings0
Affected Products
avm:fritz\!_os
Weaknesses (CWE)
CWE-310
References
http://packetstormsecurity.com/files/135161/AVM-FRITZ-Box-Arbitrary-Code-Execution-Via-Firmware-Images.html(cve@mitre.org)
http://seclists.org/fulldisclosure/2016/Jan/12(cve@mitre.org)
http://www.securityfocus.com/archive/1/537246/100/0/threaded(cve@mitre.org)
https://avm.de/service/sicherheitsinfos-zu-updates/(cve@mitre.org)
https://www.redteam-pentesting.de/advisories/rt-sa-2014-014(cve@mitre.org)
http://packetstormsecurity.com/files/135161/AVM-FRITZ-Box-Arbitrary-Code-Execution-Via-Firmware-Images.html(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2016/Jan/12(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/archive/1/537246/100/0/threaded(af854a3a-2127-422b-91ae-364da2661108)
https://avm.de/service/sicherheitsinfos-zu-updates/(af854a3a-2127-422b-91ae-364da2661108)
https://www.redteam-pentesting.de/advisories/rt-sa-2014-014(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.