Vulnerability record · CVE-2014-9583 · published 8 January 2015
CVE-2014-9583: ASUS WRT infosvr Missing MAC Check Allows Command Execution
T Mobile · Tm Ac1900
The infosvr component in ASUS WRT firmware fails to validate the MAC address on incoming requests, so authentication can be bypassed. A remote attacker can send a crafted NET_CMD_ID_MANU_CMD packet to UDP port 9999 and execute arbitrary commands on affected routers such as the RT-AC66U and RT-N66U.
Description
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other routers, does not properly check the MAC address for a request, which allows remote attackers to bypass authentication and execute arbitrary commands via a NET_CMD_ID_MANU_CMD packet to UDP port 9999. NOTE: this issue was incorrectly mapped to CVE-2014-10000, but that ID is invalid due to its use as an example of the 2014 CVE ID syntax change.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityThe flaw allows unauthenticated remote command execution with a CVSS 2.0 score of 10, public exploits are available and EPSS is very high.
What it is
The infosvr component in ASUS WRT firmware fails to validate the MAC address on incoming requests, so authentication can be bypassed. A remote attacker can send a crafted NET_CMD_ID_MANU_CMD packet to UDP port 9999 and execute arbitrary commands on affected routers such as the RT-AC66U and RT-N66U.
Impact
An unauthenticated attacker gains full command execution on the router, leading to complete compromise of confidentiality, integrity and availability. This can enable persistent access, traffic interception and use of the device as a pivot into the internal network.
Attack surface
Reachable over the network via UDP port 9999 with no authentication required, as reflected by the AV:N/AC:L/Au:N vector. No user interaction is described in the record.
Exploitation
Multiple public exploit references exist, including Packet Storm, Exploit-DB and a GitHub tool, and EPSS is very high at 0.80235 (99.6th percentile). The CVE is not listed in CISA KEV, so there is no confirmed in-the-wild exploitation record here.
What to do
- Apply the vendor firmware update for the affected ASUS WRT and T-Mobile TM-AC1900 devices as soon as possible.
- If no patch is available, block or restrict UDP port 9999 on the router's WAN and LAN interfaces.
- Disable or remove the infosvr service if it is not required.
- Replace end-of-life routers that no longer receive firmware updates.
- Segment router management and internal networks to limit lateral movement if a device is compromised.
Detection
- Monitor for unexpected UDP traffic to port 9999 on router interfaces.
- Alert on NET_CMD_ID_MANU_CMD packets or infosvr process activity in router logs where available.
- Watch for anomalous outbound connections or new processes on the router that may indicate command execution.
- Audit router firmware versions against the affected ASUS WRT builds and T-Mobile TM-AC1900.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-9583 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-9583), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.