CVE-2014-9727: Avm Fritz!box

High severity, CVSS 10.0. EPSS: 72.1% chance of exploitation in the next 30 days.

AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter to cgi-bin/webcm.

Affected products

  • Avm Fritz!box: any version

Published 2015-05-29. Last modified 2026-06-17.