CVE-2017-14135 is a critical remote code execution vulnerability affecting the webadmin plugin in OpenDreambox 2.0.0. Attackers can exploit this flaw by injecting shell metacharacters into the 'command' parameter of the /script URI, allowing arbitrary OS command execution. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk, enabling complete compromise of affected systems. While not listed in CISA's KEV catalog, public Nuclei templates exist, and it has garnered community discussion and media coverage, including its association with the Gitpaste-12 botnet, suggesting active exploitation potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:dreambox:opendreambox:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.