CVE-2014-8389
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware LM.1.6.17.01 uses hard-coded credentials in the embedded Boa web server, which allows remote attackers to obtain user credentials via crafted HTTP requests.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.43_21.08.2014 |
| Running on/with | Platform Versions |
|---|---|
Airlive Bu 3026 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.81_21.08.2014 |
| Running on/with | Platform Versions |
|---|---|
Airlive Md 3025 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version lm.1.6.18_14.10.2011 |
| Running on/with | Platform Versions |
|---|---|
Airlive Wl 2000cam | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version lm.1.6.17.01 |
| Running on/with | Platform Versions |
|---|---|
Airlive Poe 200cam V2 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.03.18_16.06.2014 |
| Running on/with | Platform Versions |
|---|---|
Airlive Bu 2015 | All versions |
References (10)
Source: cve@mitre.org
ExploitMitigationThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitMailing ListMitigationThird Party Advisory
Source: cve@mitre.org
Source: cve@mitre.org
ExploitMitigationThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitMitigationTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationTechnical DescriptionThird Party Advisory
Timeline
No history available yet.