DrayTek VigorACS 2 Unsafe Flex AMF Java Object Deserialization

Discussion in 'News Aggregator' started by Packet Storm, 21 Apr 2018.

  1. Packet Storm

    Packet Storm Guest

    DrayTek Vigor ACS server, a remote enterprise management system for DrayTek routers, uses a vulnerable version of the Adobe / Apache Flex Java library that has a deserialisation vulnerability. This can be exploited by an unauthenticated attacker to achieve remote code execution as root / SYSTEM on all versions until 2.2.2. Exploit code included.

    Continue reading...
     

Share This Page

Loading...