CVE-2017-8331 is a high-severity command injection vulnerability affecting Securifi Almond, Almond+, and Almond 2015 devices running firmware AL-R096. An authenticated attacker can exploit this by manipulating POST parameters when adding port forwarding rules, leading to arbitrary command execution and full device compromise. With a CVSS score of 8.8, it has a low attack complexity and network attack vector, allowing high impact on confidentiality, integrity, and availability. While it is on a "Hot List," there is currently no public exploit code available in Metasploit, Nuclei, or ExploitDB, and no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
al-r096CPE matchmatch criteria | cpe:2.3:o:securifi:almond_2015_firmware:al-r096:*:*:*:*:*:*:* | ||
al-r096CPE matchmatch criteria | cpe:2.3:o:securifi:almond\+firmware:al-r096:*:*:*:*:*:*:* | ||
al-r096CPE matchmatch criteria | cpe:2.3:o:securifi:almond_firmware:al-r096:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.