← Back

CVE-2017-6079

nvd nist
Published: May 16, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application: if the command is valid, it executes. An example is the wget command. The page that allows this has been confirmed in firmware as old as 2006.

Affected (1)

Edgemarc Firmware
Configuration A
1 vulnerable · 10 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Ribboncommunications
Edgemarc 4550
All versions
Ribboncommunications
Edgemarc 4552
All versions
Ribboncommunications
Edgemarc 4601
All versions
Ribboncommunications
Edgemarc 4700
All versions
Ribboncommunications
Edgemarc 4750
All versions
Ribboncommunications
Edgemarc 4800
All versions
Ribboncommunications
Edgemarc 4806
All versions
Ribboncommunications
Edgemarc 4808
All versions
Ribboncommunications
Edgemarc 7301
All versions
Ribboncommunications
Edgemarc 7400
All versions

References (2)

Source: cve@mitre.org
ExploitTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory

Timeline

No history available yet.