CVE-2007-4733
Estado: ModificadaAlta (9.3)—
The Aztech DSL600EU router, when WAN access to the web interface is disabled, does not properly block inbound traffic on TCP port 80, which allows remote attackers to connect to the web interface by guessing a TCP sequence number, possibly involving spoofing of an ARP packet, a related issue to CVE-1999-0077.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.85%
- Percentil entre todas las CVEs puntuadas: 78
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://osvdb.org/45877
- http://securityreason.com/securityalert/3093
- http://securitytracker.com/id?1018641
- http://www.securityfocus.com/archive/1/478314/100/0/threaded
- http://osvdb.org/45877
- http://securityreason.com/securityalert/3093
- http://securitytracker.com/id?1018641
- http://www.securityfocus.com/archive/1/478314/100/0/threaded
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-4733",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-09-06T19:17:00.000",
"references": [
{
"url": "http://osvdb.org/45877",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3093",
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1018641",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/478314/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/45877",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3093",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1018641",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/478314/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Aztech DSL600EU router, when WAN access to the web interface is disabled, does not properly block inbound traffic on TCP port 80, which allows remote attackers to connect to the web interface by guessing a TCP sequence number, possibly involving spoofing of an ARP packet, a related issue to CVE-1999-0077."
},
{
"lang": "es",
"value": "El router Aztech DSL600EU, cuando el acceso WAN al interfaz web está deshabilitado, no bloquea apropiadamente el tráfico entrante en el puerto 80 TCP, lo que permite a atacantes remotos conectarse al interfaz Web adivinando el número de la secuencia TCP, posiblemente suplantando un paquete ARP. Vulnerabilidad relacionada con la CVE-1999-0077."
}
],
"lastModified": "2026-06-16T22:44:40.423",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:aztech:dsl_600eu_router:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "56F0E7C4-5D9A-45DF-903B-9086F57439B1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}