← Vulnerability feed

Vulnerability record · CVE-2014-9583 · published 8 January 2015

CVE-2014-9583: ASUS WRT infosvr Missing MAC Check Allows Command Execution

T Mobile · Tm Ac1900

The infosvr component in ASUS WRT firmware fails to validate the MAC address on incoming requests, so authentication can be bypassed. A remote attacker can send a crafted NET_CMD_ID_MANU_CMD packet to UDP port 9999 and execute arbitrary commands on affected routers such as the RT-AC66U and RT-N66U.

10.0 CVSS 2.0 High EPSS 80% · top 0.4% CWE-264 · Permissions and access controls
10.0CVSS 2.0 base score
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the MAC address for a request, which allows remote attackers to bypass authentication and execute arbitrary commands via a NET_CMD_ID_MANU_CMD packet to UDP port 9999. NOTE: this issue was incorrectly mapped to CVE-2014-10000, but that ID is invalid due to its use as an example of the 2014 CVE ID syntax change.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityThe flaw allows unauthenticated remote command execution with a CVSS 2.0 score of 10, public exploits are available and EPSS is very high.

What it is

The infosvr component in ASUS WRT firmware fails to validate the MAC address on incoming requests, so authentication can be bypassed. A remote attacker can send a crafted NET_CMD_ID_MANU_CMD packet to UDP port 9999 and execute arbitrary commands on affected routers such as the RT-AC66U and RT-N66U.

Impact

An unauthenticated attacker gains full command execution on the router, leading to complete compromise of confidentiality, integrity and availability. This can enable persistent access, traffic interception and use of the device as a pivot into the internal network.

Attack surface

Reachable over the network via UDP port 9999 with no authentication required, as reflected by the AV:N/AC:L/Au:N vector. No user interaction is described in the record.

Exploitation

Multiple public exploit references exist, including Packet Storm, Exploit-DB and a GitHub tool, and EPSS is very high at 0.80235 (99.6th percentile). The CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record here.

What to do

  • Apply the vendor firmware update for the affected ASUS WRT and T-Mobile TM-AC1900 devices as soon as possible.
  • If no patch is available, block or restrict UDP port 9999 on the router's WAN and LAN interfaces.
  • Disable or remove the infosvr service if it is not required.
  • Replace end-of-life routers that no longer receive firmware updates.
  • Segment router management and internal networks to limit lateral movement if a device is compromised.

Detection

  • Monitor for unexpected UDP traffic to port 9999 on router interfaces.
  • Alert on NET_CMD_ID_MANU_CMD packets or infosvr process activity in router logs where available.
  • Watch for anomalous outbound connections or new processes on the router that may indicate command execution.
  • Audit router firmware versions against the affected ASUS WRT builds and T-Mobile TM-AC1900.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-9583 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.5CVE-2013-5948T-mobile tm-ac1900 os command injection vulnerabilityThe Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows re…EPSS 9.5%7.2CVE-2013-1813Redhat enterprise linux permissions and access controls vulnerabilityutil-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows lo…EPSS 0.62%7.1CVE-2014-2718T-mobile tm-ac1900 insufficient verification of data authenticity vulnerabilityASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0…EPSS 1.1%6.8CVE-2011-2716T-mobile tm-ac1900 improper input validation vulnerabilityThe DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_N…EPSS 1.8%6.3CVE-2014-2719Asus rt-ac66u firmware information exposure vulnerabilityAdvanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator session is active, allows remo…EPSS 1.1%4.3CVE-2014-2925T-mobile tm-ac1900 cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Advanced_Wireless_Content.asp in ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.3…EPSS 1.2%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed6.6CVE-2015-1769Windows Mount Manager symlink mishandling allows local privilege escalationThe Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core…KEVEPSS 4.1%analysed

Source: NIST National Vulnerability Database (record CVE-2014-9583), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.