CVE-2009-1167

CRITICAL

Unspecified vulnerability on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0 and 5.x before 5.2.191.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 420...

Affects 7 products across 1 vendor.

BCS7.33
CVSS 2.010.0
EPSS2.1%
Percentile81th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ AI Analysis — automated analysis, not human-reviewed

This vulnerability was disclosed in 2009. A critical vulnerability affects Cisco systems (CVE-2009-1167). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2009-GLOBAL-312021-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2009-1167?
This vulnerability was disclosed in 2009. A critical vulnerability affects Cisco systems (CVE-2009-1167). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2009-1167?
CVE-2009-1167 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 2.1%.
Is CVE-2009-1167 actively exploited?
No confirmed active exploitation of CVE-2009-1167 as of 2026-09-25.
How do I remediate CVE-2009-1167?
Priority: MEDIUM. Advisory: http://www.cisco.com/en/US/products/products_security_advisory09186a0080adb3d7.shtml PSIRT: [email protected]
What systems are affected by CVE-2009-1167?
CVE-2009-1167 affects: Cisco, Cisco, Cisco, Cisco, Cisco, Cisco, Cisco.
Vulnerability Details
CVE IDCVE-2009-1167
BSIDBS-2009-GLOBAL-312021-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2009-07-29
Last Modified2026-06-16
ICS Relevance75%
Domains
NETWORK-INFRA
SourceNVD
Official Description

Unspecified vulnerability on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0 and 5.x before 5.2.191.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Modules (WiSM), WLC Modules for Integrated Services Routers, and Catalyst 3750G Integrated Wireless LAN Controllers, allows remote attackers to modify the configuration via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCsy44672.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Unspecified vulnerability on the Cisco Wireless LAN Controller (WLC) platform 4.x before 4.2.205.0 and 5.x before 5.2.191.0, as used in Cisco 1500 Series, 2000 Series, 2100 Series, 4100 Series, 4200 Series, and 4400 Series Wireless Services Modules (WiSM), WLC Modules for Integrated Services Routers, and Catalyst 3750G Integrated Wireless LAN Controllers, allows remote attackers to modify the configuration via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCsy44672. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Cisco Catalyst 3750G —
Cisco Cisco 1500 Wireless Lan Controller —
Cisco Cisco 2000 Wireless Lan Controller —
Cisco Cisco 2100 Wireless Lan Controller —
Cisco Cisco 4100 Wireless Lan Controller —
Cisco Cisco 4200 Wireless Lan Controller —
Cisco Cisco 4400 Wireless Lan Controller —
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 6269 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash58d0fb9ae739abbd40eb3f883e93f95355a07f1fbeafd3433ff38f3916cc71eb912d81a61d7f0a69861307665d411db7ec1bb5c12f73e8e66fdc3a0964015b2a
Related CVEs affecting Cisco
CVE-2007-1257 10.0 The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 76... CVE-2007-4241 10.0 Buffer overflow in ldcconn in Hewlett-Packard (HP) Controller for Cisco Local... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2009-4912 10.0 Cisco Adaptive Security Appliances (ASA) 5580 series devices with software be... CVE-2009-4919 10.0 Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5580 series devic...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →