Vulnerabilities > CVE-2009-1807 - Unspecified vulnerability in Baofeng Storm

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
baofeng
critical
exploit available

Summary

Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009.

Vulnerable Configurations

Part Description Count
Application
Baofeng
5

Exploit-Db

descriptionBaoFeng (config.dll) ActiveX Remote Code Execution Exploit. CVE-2009-1807. Remote exploit for windows platform
idEDB-ID:8757
last seen2016-02-01
modified2009-05-21
published2009-05-21
reporteretirah
sourcehttps://www.exploit-db.com/download/8757/
titleBaoFeng config.dll ActiveX Remote Code Execution Exploit