CVE-2017-11587: Cisco Residential Gateway Firmware
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is directory traversal in the filename parameter to the /download.conf URI.
Affected products
- Cisco Residential Gateway Firmware: version ddr2200b-na-annexa-fcc-v00.00.03.45.4e only; version ddr2201v1-na-annexa-fcc-v00.00.03.28.3 only
Published 2017-07-24. Last modified 2026-06-17.