CVE-2014-3150
UnknownEPSS 1.86%
Last modified
CVE-2014-3150 is a vulnerability of currently unknown severity. Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript.. EPSS estimates a 1.86% chance of exploitation in the next 30 days.
Description
Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Orange | Livebox 1.1 Firmware | 26014a |
References
- https://archive.fo/TZQpDThird Party Advisory
- https://archive.fo/TZQpDThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-3150?
Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript.
How severe is CVE-2014-3150?
Severity scoring for CVE-2014-3150 is pending analysis. The EPSS model estimates a 1.86% probability of exploitation in the next 30 days.
How do I fix CVE-2014-3150?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-3144The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST exten…
- CVE-2014-3145The BPF_S_ANC_NLATTR_NEST extension implementation in the sk…
- CVE-2014-3146Incomplete blacklist vulnerability in the lxml.html.clean mo…6.1
- CVE-2014-3147Cross-site scripting (XSS) vulnerability in the auto-complet…
- CVE-2014-3148Cross-site scripting (XSS) vulnerability in libahttp/err.c i…
- CVE-2014-3149Cross-site scripting (XSS) vulnerability in Invision Power I…
- CVE-2014-3152Integer underflow in the LCodeGen::PrepareKeyedOperand funct…
- CVE-2014-3153The futex_requeue function in kernel/futex.c in the Linux ke…7.8
- CVE-2014-3154Use-after-free vulnerability in the ChildThread::Shutdown fu…
- CVE-2014-3155net/spdy/spdy_write_queue.cc in the SPDY implementation in G…
- CVE-2014-3156Buffer overflow in the clipboard implementation in Google Ch…
- CVE-2014-3157Heap-based buffer overflow in the FFmpegVideoDecoder::GetVid…
Are you affected by CVE-2014-3150?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
