CVE-2017-11589: Cisco Residential Gateway Firmware
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is no access control for info.html, wancfg.cmd, rtroutecfg.cmd, arpview.cmd, cpuview.cmd, memoryview.cmd, statswan.cmd, statsatm.cmd, scsrvcntr.cmd, scacccntr.cmd, logview.cmd, voicesipview.cmd, usbview.cmd, wlmacflt.cmd, wlwds.cmd, wlstationlist.cmd, HPNAShow.cmd, HPNAView.cmd, qoscls.cmd, qosqueue.cmd, portmap.cmd, scmacflt.cmd, scinflt.cmd, scoutflt.cmd, certlocal.cmd, or certca.cmd.
Affected products
- Cisco Residential Gateway Firmware: version ddr2200b-na-annexa-fcc-v00.00.03.45.4e only; version ddr2201v1-na-annexa-fcc-v00.00.03.28.3 only
Published 2017-07-24. Last modified 2026-06-17.