Vulnerability record · CVE-2014-0659 · published 12 January 2014
CVE-2014-0659: Cisco WAP4410N, WRVS4400N and RVS4000 command injection via TCP port 32764
Cisco · Rvs4000 Firmware
Cisco WAP4410N access points, WRVS4400N and RVS4000 routers expose a test interface on TCP port 32764 that fails to properly handle requests, allowing OS command injection (CWE-78). An unauthenticated remote attacker can read credential and configuration data and execute arbitrary commands on the device. The flaw affects firmware versions through 2.0.6.1 (WAP4410N), 1.x through 1.1.13 and 2.x through 2.0.2.1 (WRVS4400N), and through 2.0.3.2 (RVS4000).
Description
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote command execution and credential disclosure with a CVSS 2.0 base score of 10 and very high EPSS probability on internet-facing edge devices.
What it is
Cisco WAP4410N access points, WRVS4400N and RVS4000 routers expose a test interface on TCP port 32764 that fails to properly handle requests, allowing OS command injection (CWE-78). An unauthenticated remote attacker can read credential and configuration data and execute arbitrary commands on the device. The flaw affects firmware versions through 2.0.6.1 (WAP4410N), 1.x through 1.1.13 and 2.x through 2.0.2.1 (WRVS4400N), and through 2.0.3.2 (RVS4000).
Impact
An attacker gains full read access to stored credentials and device configuration plus the ability to run arbitrary commands, effectively taking complete control of the affected device.
Attack surface
Reachable over the network via requests to the test interface on TCP port 32764; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.738 probability, 99.45th percentile), and a public GitHub repository (elvanderb/TCP-32764) tagged Issue Tracking/Patch documents the port 32764 interface, indicating public technical detail exists.
What to do
- Apply the fixed firmware from Cisco's advisory cisco-sa-20140110-sbd for each affected model; if no fix is available for a model, replace the device.
- Block or filter inbound and outbound TCP port 32764 at network boundaries and on the devices themselves.
- Isolate affected access points and routers on a segmented management network with no exposure to untrusted networks.
- Rotate any credentials, keys or configuration secrets stored on or passed through the affected devices.
- Monitor vendor advisories for end-of-support status and plan hardware replacement where firmware updates are no longer issued.
Detection
- Monitor network traffic for TCP connections to port 32764 on Cisco WAP4410N, WRVS4400N and RVS4000 devices.
- Alert on unexpected outbound connections or command execution artifacts originating from these devices.
- Audit device configurations and logs for unauthorized changes or credential access attempts.
- Scan the network for hosts exposing TCP port 32764 and correlate with the affected Cisco model inventory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-0659 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0659), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.