CVE-2014-0659
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remo...
Affects 6 products across 1 vendor.
Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A critical vulnerability in Cisco WAP4410N, WRVS4400N, and RVS4000 devices allows remote attackers to read credentials and configuration data, and execute arbitrary commands through an unsecured test interface on TCP port 32764.
BSID: BS-2014-GLOBAL-157041-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2014-0659?
What is the CVSS score for CVE-2014-0659?
Is CVE-2014-0659 actively exploited?
How do I remediate CVE-2014-0659?
What systems are affected by CVE-2014-0659?
| CVE ID | CVE-2014-0659 |
|---|---|
| BSID | BS-2014-GLOBAL-157041-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2014-01-12 |
| Last Modified | 2026-04-29 |
| ICS Relevance | 100% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and execute arbitrary commands, via requests to the test interface on TCP port 32764, aka Bug IDs CSCum37566, CSCum43693, CSCum43700, and CSCum43685.
Source: NIST NVD / MITRE CVE Database
The vulnerability is exploited by sending specially crafted requests to the test interface on TCP port 32764, which is accessible remotely. This allows attackers to gain unauthorized access to sensitive information and execute arbitrary commands on the affected devices.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Cisco | Rvs4000 | — |
| Cisco | Wrvs4400N | — |
| Cisco | Rvs4000 Firmware | — |
| Cisco | Wrvs4400N Firmware | — |
| Cisco | Wap4410N Firmware | — |
| Cisco | Wap4410N | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →