DrayTek VigorACS 2 Unsafe Flex AMF Java Object Deserialization
Posted by deepcore on April 22, 2018 – 7:49 am
DrayTek Vigor ACS server, a remote enterprise management system for DrayTek routers, uses a vulnerable version of the Adobe / Apache Flex Java library that has a deserialisation vulnerability. This can be exploited by an unauthenticated attacker to achieve remote code execution as root / SYSTEM on all versions until 2.2.2. Exploit code included.
Post a reply
You must be logged in to post a comment.