Title: Aztech ADSL2/2+ /cgi-bin/script system Variable Arbitrary Command Execution
Info
Disclosure
Mar 25, 2008
Discovery
Unknown
Dates
Exploit
Mar 25, 2008
Solution
Unknown
Description
Aztech ADSL2/2+ 4 Port Router firmware version 3.7.0 contains a flaw that may allow a malicious user to execute arbitrary commands with root privileges. The issue is triggered when an arbitrary command is sent to the /cgi-bin/script?system variable. It is possible that the flaw may allow remote root access resulting in a loss of confidentiality, integrity, and availability.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity,
Loss of Availability
Solution:
Solution Unknown
Exploit:
Exploit Available
Disclosure:
Uncoordinated Disclosure
OSVDB:
Web Related
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.