CVE-2014-0659

CRITICAL ⚠ Exploit

The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remo...

Affects 6 products across 1 vendor.

BCS8.97
CVSS 2.010.0
EPSS73.8%
Percentile99th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-78
CAPEC-88 OS Command Injection
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in Cisco WAP4410N, WRVS4400N, and RVS4000 devices allows remote attackers to read credentials and configuration data, and execute arbitrary commands through an unsecured test interface on TCP port 32764.

BSID: BS-2014-GLOBAL-157041-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2014-0659?
A critical vulnerability in Cisco WAP4410N, WRVS4400N, and RVS4000 devices allows remote attackers to read credentials and configuration data, and execute arbitrary commands through an unsecured test interface on TCP port 32764.
What is the CVSS score for CVE-2014-0659?
CVE-2014-0659 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 73.8%.
Is CVE-2014-0659 actively exploited?
Public exploit available for CVE-2014-0659. Exploitation risk elevated.
How do I remediate CVE-2014-0659?
Priority: IMMEDIATE. Advisory: https://github.com/elvanderb/TCP-32764 PSIRT: [email protected]
What systems are affected by CVE-2014-0659?
CVE-2014-0659 affects: Cisco, Cisco, Cisco, Cisco, Cisco, Cisco.
Vulnerability Details
CVE IDCVE-2014-0659
BSIDBS-2014-GLOBAL-157041-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2014-01-12
Last Modified2026-04-29
ICS Relevance100%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited by sending specially crafted requests to the test interface on TCP port 32764, which is accessible remotely. This allows attackers to gain unauthorized access to sensitive information and execute arbitrary commands on the affected devices.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cisco Rvs4000
Cisco Wrvs4400N
Cisco Rvs4000 Firmware
Cisco Wrvs4400N Firmware
Cisco Wap4410N Firmware
Cisco Wap4410N
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 4586 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Cisco
CVE-2008-0529 10.0 Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, ... CVE-2008-0029 10.0 Cisco Application Velocity System (AVS) before 5.1.0 is installed with defaul... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues... CVE-2003-1096 10.0 The Cisco LEAP challenge/response authentication mechanism uses passwords in ... CVE-1999-0775 10.0 Cisco Gigabit Switch routers running IOS allow remote attackers to forward un...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →