CVE-2014-8389

UnknownEPSS 50.49%

Last modified

CVE-2014-8389 is a vulnerability of currently unknown severity. cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware LM.1.6.17.01 uses hard-coded credentials in the embedded Boa web server, which allows remote attackers to obtain user credentials via crafted HTTP requests.. EPSS estimates a 50.49% chance of exploitation in the next 30 days.

Description

cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware LM.1.6.17.01 uses hard-coded credentials in the embedded Boa web server, which allows remote attackers to obtain user credentials via crafted HTTP requests.

Metrics

EPSS Probability
50.49%

98.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AirliveBu-3026 Firmware1.43_21.08.2014
AirliveMd-3025 Firmware1.81_21.08.2014
AirliveWl-2000cam Firmwarelm.1.6.18_14.10.2011
AirlivePoe-200cam V2 Firmwarelm.1.6.17.01
AirliveBu-2015 Firmware1.03.18_16.06.2014

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-8389?
cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware LM.1.6.17.01 uses hard-coded credentials in the embedded Boa web server, which allows remote attackers to obtain user credentials via crafted HTTP requests.
How severe is CVE-2014-8389?
Severity scoring for CVE-2014-8389 is pending analysis. The EPSS model estimates a 50.49% probability of exploitation in the next 30 days.
How do I fix CVE-2014-8389?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-8389?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST