CVE detail
CVE-2015-7279
Amped Wireless R10000 devices with firmware 2.5.2.11 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
- Wireless Routers Plagued by Unpatched FlawsSecurityWeek
Wireless SOHO routers from ZyXEL, Belkin, ReadyNet, Amped Wireless, Buffalo and Netgear are plagued by multiple unpatched vulnerabilities, researchers have warned. Vulnerabilities in Belkin Routers Security researcher John Garrett of Ethical Reporting informed SecurityWeek that he has identified multiple vulnerabilities in Belkin AC-1750, AC-1200, N-600 and N-150 routers. The expert reported finding various flaws in each model, including path traversals that can be used to access potentially sensitive APIs, weaknesses that allow unauthenticated attackers to alter the settings of a device, authentication bypass, and remote code execution vulnerabilities. Garrett has published videos showing how the vulnerabilities can be exploited against routers running the latest version of the firmware available from Belkin. He also pointed out that Belkin and Belkin-owned Linksys routers have a firmware update feature that introduces a backdoor on the devices. Belkin told the expert that it’s worki…
newswww.securityweek.comDec 14, 2015, 1:47 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
2 related CVEs with shared weakness or product evidence
- CVE-2015-7278CVSS 8.8 · High
Cross-site request forgery (CSRF) vulnerability on Amped Wireless R10000 devices with firmware 2.5.2.11 allows remote attackers to hijack the authentication of arbitrary users.
- CVE-2015-7277CVSS 9.8 · Critical
The web administration interface on Amped Wireless R10000 devices with firmware 2.5.2.11 has a default password of admin for the admin account, which allows remote attackers to ob…