← All CVEs

CVE-2014-8387

high · 9

cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.

9
CVSS
30.9%
EPSS (exploit prob.)
98th
EPSS percentile
2014-11-20
Published

AV:N/AC:L/Au:S/C:C/I:C/A:C

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
advantecheki-6340_firmware2.05
advantecheki-6340all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-8387