← Vulnerability feed

Vulnerability record · CVE-2014-0659 · published 12 January 2014

CVE-2014-0659: Cisco WAP4410N, WRVS4400N and RVS4000 command injection via TCP port 32764

Cisco · Rvs4000 Firmware

Cisco WAP4410N access points, WRVS4400N and RVS4000 routers expose a test interface on TCP port 32764 that fails to properly handle requests, allowing OS command injection (CWE-78). An unauthenticated remote attacker can read credential and configuration data and execute arbitrary commands on the device. The flaw affects firmware versions through 2.0.6.1 (WAP4410N), 1.x through 1.1.13 and 2.x through 2.0.2.1 (WRVS4400N), and through 2.0.3.2 (RVS4000).

10.0 CVSS 2.0 High EPSS 74% · top 0.5% CWE-78 · OS command injection
10.0CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution and credential disclosure with a CVSS 2.0 base score of 10 and very high EPSS probability on internet-facing edge devices.

What it is

Cisco WAP4410N access points, WRVS4400N and RVS4000 routers expose a test interface on TCP port 32764 that fails to properly handle requests, allowing OS command injection (CWE-78). An unauthenticated remote attacker can read credential and configuration data and execute arbitrary commands on the device. The flaw affects firmware versions through 2.0.6.1 (WAP4410N), 1.x through 1.1.13 and 2.x through 2.0.2.1 (WRVS4400N), and through 2.0.3.2 (RVS4000).

Impact

An attacker gains full read access to stored credentials and device configuration plus the ability to run arbitrary commands, effectively taking complete control of the affected device.

Attack surface

Reachable over the network via requests to the test interface on TCP port 32764; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.738 probability, 99.45th percentile), and a public GitHub repository (elvanderb/TCP-32764) tagged Issue Tracking/Patch documents the port 32764 interface, indicating public technical detail exists.

What to do

  • Apply the fixed firmware from Cisco's advisory cisco-sa-20140110-sbd for each affected model; if no fix is available for a model, replace the device.
  • Block or filter inbound and outbound TCP port 32764 at network boundaries and on the devices themselves.
  • Isolate affected access points and routers on a segmented management network with no exposure to untrusted networks.
  • Rotate any credentials, keys or configuration secrets stored on or passed through the affected devices.
  • Monitor vendor advisories for end-of-support status and plan hardware replacement where firmware updates are no longer issued.

Detection

  • Monitor network traffic for TCP connections to port 32764 on Cisco WAP4410N, WRVS4400N and RVS4000 devices.
  • Alert on unexpected outbound connections or command execution artifacts originating from these devices.
  • Audit device configurations and logs for unauthorized changes or credential access attempts.
  • Scan the network for hosts exposing TCP port 32764 and correlate with the affected Cisco model inventory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-0659 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2011-1645Cisco rvs4000 vulnerabilityThe web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N …EPSS 3.4%9.0CVE-2011-1646Cisco rvs4000 code injection vulnerabilityThe web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N …EPSS 1.9%9.0CVE-2010-0593Cisco pvc2300 permissions and access controls vulnerabilityThe Cisco RVS4000 4-port Gigabit Security Router before 1.3.2.0, PVC2300 Business Internet Video Camera before 1.1.2.6, WVC200 Wireless-G PTZ Interne…EPSS 3.0%5.9CVE-2015-6358Cisco rv320 firmware improper certificate validation vulnerabilityMultiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat …EPSS 1.3%5.0CVE-2011-1647Cisco rvs4000 information exposure vulnerabilityThe web management interface on the Cisco RVS4000 Gigabit Security Router with software 1.x before 1.3.3.4 and 2.x before 2.0.2.7, and the WRVS4400N …EPSS 1.2%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed

Source: NIST National Vulnerability Database (record CVE-2014-0659), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.