CVE-2017-6079
The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application: if the command is valid, it executes. An example is the wget command. The page that allows this has been confirmed in firmware as old as 2006.
Published:May 16, 2017
Last Modified:Apr 20, 2025
EPS:May 16, 2017
EPSS Score:0.32225
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Ribboncommunications
Product
Edgemarc 4550
Ribboncommunications
Edgemarc 4550
Vendor
Ribboncommunications
Product
Edgemarc 4552
Ribboncommunications
Edgemarc 4552
Vendor
Ribboncommunications
Product
Edgemarc 4601
Ribboncommunications
Edgemarc 4601
Vendor
Ribboncommunications
Product
Edgemarc 4700
Ribboncommunications
Edgemarc 4700
Vendor
Ribboncommunications
Product
Edgemarc 4750
Ribboncommunications
Edgemarc 4750
Vendor
Ribboncommunications
Product
Edgemarc 4800
Ribboncommunications
Edgemarc 4800
Vendor
Ribboncommunications
Product
Edgemarc 4806
Ribboncommunications
Edgemarc 4806
Vendor
Ribboncommunications
Product
Edgemarc 4808
Ribboncommunications
Edgemarc 4808
Vendor
Ribboncommunications
Product
Edgemarc 7301
Ribboncommunications
Edgemarc 7301
Vendor
Ribboncommunications
Product
Edgemarc 7400
Ribboncommunications
Edgemarc 7400
Vendor
Ribboncommunications
Product
Edgemarc Firmware
Ribboncommunications
Edgemarc Firmware
Exploits
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
