← Back

CVE-2014-1406

nvd nist
Published: Jan 10, 2014Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

CRLF injection vulnerability in goform/formWlSiteSurvey on the Conceptronic C54APM access point with runtime code 1.26 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the submit-url parameter in a Refresh action.

Affected (2)

2 products
C54apm Firmware
C54apm
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.26
Version v2

References (2)

Timeline

No history available yet.