CVE-2015-2054: CRLF Injection
CRLF injection vulnerability in export.cfg in the web-based administrative console for Sierra Wireless AirCard 760S, 762S, and 763S allows remote attackers to inject arbitrary headers via CRLF sequences in the save parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2054?
CVE-2015-2054 is considered a medium-severity vulnerability due to the potential for remote header injection.
How do I fix CVE-2015-2054?
To fix CVE-2015-2054, apply any available firmware updates for the Sierra Wireless AirCard 760S, 762S, and 763S models.
Who is affected by CVE-2015-2054?
CVE-2015-2054 affects users of the Sierra Wireless AirCard 760S, 762S, and 763S devices.
What type of attack can CVE-2015-2054 enable?
CVE-2015-2054 can enable remote attackers to perform HTTP response splitting attacks through header injection.
Is CVE-2015-2054 easy to exploit?
Yes, CVE-2015-2054 can be exploited easily by attackers who can send crafted requests to the affected devices.