← Vulnerability feed

Vulnerability record · CVE-2017-6079 · published 16 May 2017

CVE-2017-6079: Edgewater Edgemarc web management hidden page allows command execution

Ribboncommunications · Edgemarc Firmware

The HTTP web-management application on Edgewater Networks Edgemarc appliances exposes a hidden page that accepts user-defined commands, including iptables routes, and executes them server-side. It functions as a web shell with no client-side feedback, and the page has been confirmed in firmware as old as 2006. Because commands run without authentication or user interaction, any network-reachable device is at risk.

9.8 CVSS 3.1 Critical EPSS 47% · top 1.2%
9.8CVSS 3.1 base score, v2 10.0
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application: if the command is valid, it executes. An example is the wget command. The page that allows this has been confirmed in firmware as old as 2006.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required and public exploit detail, though KEV listing is absent.

What it is

The HTTP web-management application on Edgewater Networks Edgemarc appliances exposes a hidden page that accepts user-defined commands, including iptables routes, and executes them server-side. It functions as a web shell with no client-side feedback, and the page has been confirmed in firmware as old as 2006. Because commands run without authentication or user interaction, any network-reachable device is at risk.

Impact

An attacker gains arbitrary command execution on the appliance, allowing them to alter routing and firewall rules, pivot into the network, or run tools such as wget to pull additional payloads. Full compromise of confidentiality, integrity and availability is possible.

Attack surface

Reached over the network via the HTTP web-management interface on the hidden page; the CVSS vector indicates no privileges and no user interaction are required. Any host that can reach the management interface can attempt it.

Exploitation

Not listed in CISA KEV, but EPSS is 0.46846 (98.8th percentile) and the only references are tagged Exploit and Technical Description, indicating public exploit detail exists. No ransomware group usage is documented.

What to do

  • Apply the vendor firmware update for Edgemarc appliances; if no fixed version is available, contact Edgewater/Ribbon for guidance.
  • Restrict access to the HTTP management interface to trusted management networks and block it from untrusted networks.
  • Disable or remove the hidden command page if the firmware permits, and audit for other undocumented endpoints.
  • Replace end-of-life firmware versions (confirmed as old as 2006) with supported releases.
  • Monitor and log all requests to the web-management application for unexpected command-like parameters.

Detection

  • Review web server and appliance logs for requests to undocumented or hidden pages on the management interface.
  • Alert on outbound connections from Edgemarc appliances to unexpected destinations, especially wget-style downloads.
  • Baseline and monitor iptables and routing table changes on the appliance for unauthorized modifications.
  • Scan the management interface for the hidden page and other undocumented endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-6079 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2017-6079), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.