CVE-2014-9583: Critical severity T-Mobile Tm-ac1900 vulnerability
common.c in infosvr in ASUS WRT firmware 3.0.0.4.3761071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the MAC address for a request, which allows remote attackers to bypass authentication and execute arbitrary commands via a NETCMDIDMANUCMD packet to UDP port 9999. NOTE: this issue was incorrectly mapped to CVE-2014-10000, but that ID is invalid due to its use as an example of the 2014 CVE ID syntax change.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9583?
CVE-2014-9583 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2014-9583?
To fix CVE-2014-9583, upgrade the affected ASUS WRT firmware to the latest version provided by the manufacturer that addresses this vulnerability.
What devices are affected by CVE-2014-9583?
Devices such as ASUS RT-AC66U, RT-N66U, and various versions of ASUS WRT firmware are affected by CVE-2014-9583.
Can CVE-2014-9583 be exploited remotely?
Yes, CVE-2014-9583 can be exploited remotely by attackers to bypass authentication and execute arbitrary commands.
What type of vulnerability is CVE-2014-9583?
CVE-2014-9583 is a command injection vulnerability that allows unauthorized command execution due to improper MAC address validation.