Vulnerability record · CVE-2017-6079 · published 16 May 2017
CVE-2017-6079: Edgewater Edgemarc web management hidden page allows command execution
Ribboncommunications · Edgemarc Firmware
The HTTP web-management application on Edgewater Networks Edgemarc appliances exposes a hidden page that accepts user-defined commands, including iptables routes, and executes them server-side. It functions as a web shell with no client-side feedback, and the page has been confirmed in firmware as old as 2006. Because commands run without authentication or user interaction, any network-reachable device is at risk.
Description
The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application: if the command is valid, it executes. An example is the wget command. The page that allows this has been confirmed in firmware as old as 2006.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and public exploit detail, though KEV listing is absent.
What it is
The HTTP web-management application on Edgewater Networks Edgemarc appliances exposes a hidden page that accepts user-defined commands, including iptables routes, and executes them server-side. It functions as a web shell with no client-side feedback, and the page has been confirmed in firmware as old as 2006. Because commands run without authentication or user interaction, any network-reachable device is at risk.
Impact
An attacker gains arbitrary command execution on the appliance, allowing them to alter routing and firewall rules, pivot into the network, or run tools such as wget to pull additional payloads. Full compromise of confidentiality, integrity and availability is possible.
Attack surface
Reached over the network via the HTTP web-management interface on the hidden page; the CVSS vector indicates no privileges and no user interaction are required. Any host that can reach the management interface can attempt it.
Exploitation
Not listed in CISA KEV, but EPSS is 0.46846 (98.8th percentile) and the only references are tagged Exploit and Technical Description, indicating public exploit detail exists. No ransomware group usage is documented.
What to do
- Apply the vendor firmware update for Edgemarc appliances; if no fixed version is available, contact Edgewater/Ribbon for guidance.
- Restrict access to the HTTP management interface to trusted management networks and block it from untrusted networks.
- Disable or remove the hidden command page if the firmware permits, and audit for other undocumented endpoints.
- Replace end-of-life firmware versions (confirmed as old as 2006) with supported releases.
- Monitor and log all requests to the web-management application for unexpected command-like parameters.
Detection
- Review web server and appliance logs for requests to undocumented or hidden pages on the management interface.
- Alert on outbound connections from Edgemarc appliances to unexpected destinations, especially wget-style downloads.
- Baseline and monitor iptables and routing table changes on the appliance for unauthorized modifications.
- Scan the management interface for the hidden page and other undocumented endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://depthsecurity.com/blog/cve-2017-6079-blind-command-injection-in-edgewater-edgemarc-devices | ExploitTechnical DescriptionThird Party Advisory |
| https://depthsecurity.com/blog/cve-2017-6079-blind-command-injection-in-edgewater-edgemarc-devices | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2017-6079 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2017-6079), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.