Vulnerability record · CVE-2014-9727 · published 29 May 2015
CVE-2014-9727: AVM Fritz!Box webcm command injection via var:lang
Avm · Fritz\!Box
AVM Fritz!Box routers pass the var:lang parameter to cgi-bin/webcm without sanitizing shell metacharacters, allowing OS command injection. The flaw is remotely reachable and unauthenticated, and public exploit code exists, so any exposed device is at immediate risk.
Description
AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote command execution with a CVSS 2.0 score of 10, public exploit code, and a very high EPSS probability make this an urgent exposure for any internet-facing Fritz!Box.
What it is
AVM Fritz!Box routers pass the var:lang parameter to cgi-bin/webcm without sanitizing shell metacharacters, allowing OS command injection. The flaw is remotely reachable and unauthenticated, and public exploit code exists, so any exposed device is at immediate risk.
Impact
An attacker can execute arbitrary commands on the router, gaining full control of the device and any traffic or credentials it handles.
Attack surface
Reached over the network via HTTP requests to cgi-bin/webcm with a crafted var:lang parameter; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.71668 (99.39th percentile) and references include an Exploit-DB entry, indicating public exploit code and active interest.
What to do
- Apply the vendor firmware update for Fritz!Box that fixes the webcm var:lang handling; if no fix is available, replace or isolate the device.
- Disable remote access to the router's web interface (cgi-bin/webcm) from the WAN side.
- Restrict management access to a trusted LAN or VPN and change default administrative credentials.
- Monitor vendor advisories and retire end-of-support Fritz!Box models that cannot be patched.
Detection
- Inspect HTTP request logs for cgi-bin/webcm requests containing shell metacharacters (;, |, $(), `) in the var:lang parameter.
- Alert on outbound connections or processes spawned by the router's web server that are unexpected for normal management traffic.
- Use the public Exploit-DB PoC (33136) to test exposure of internet-facing Fritz!Box devices in a controlled manner.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-9727 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-9727), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.