CVE-2012-2632

low
Published 2012-06-15 · Modified 2026-04-29
CVSS v3
CVSS v2
2.6
VIR risk
2.6

Description

SEIL routers with firmware SEIL/x86 1.00 through 2.35, SEIL/X1 2.30 through 3.75, SEIL/X2 2.30 through 3.75, and SEIL/B1 2.30 through 3.75, when the http-proxy and application-gateway features are enabled, do not properly handle the CONNECT command, which allows remote attackers to bypass intended URL restrictions via a TCP session.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: vultures@jpcert.or.jp — http://www.seil.jp/support/security/a01232.html

References

Verify integrity in audit chain (admin only). AS-IS.