← Retour aux CVEs
CVE-2014-8886
N/ADescription
AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote attackers to create symlinks or overwrite critical files, and consequently execute arbitrary code, via a crafted firmware image.
Details CVE
Score CVSS v3.1N/A
Publie1/8/2016
Derniere modification4/12/2025
Sourcenvd
Observations honeypot0
Produits affectes
avm:fritz\!_os
Faiblesses (CWE)
CWE-310
References
http://packetstormsecurity.com/files/135161/AVM-FRITZ-Box-Arbitrary-Code-Execution-Via-Firmware-Images.html(cve@mitre.org)
http://seclists.org/fulldisclosure/2016/Jan/12(cve@mitre.org)
http://www.securityfocus.com/archive/1/537246/100/0/threaded(cve@mitre.org)
https://avm.de/service/sicherheitsinfos-zu-updates/(cve@mitre.org)
https://www.redteam-pentesting.de/advisories/rt-sa-2014-014(cve@mitre.org)
http://packetstormsecurity.com/files/135161/AVM-FRITZ-Box-Arbitrary-Code-Execution-Via-Firmware-Images.html(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/fulldisclosure/2016/Jan/12(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/archive/1/537246/100/0/threaded(af854a3a-2127-422b-91ae-364da2661108)
https://avm.de/service/sicherheitsinfos-zu-updates/(af854a3a-2127-422b-91ae-364da2661108)
https://www.redteam-pentesting.de/advisories/rt-sa-2014-014(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.