← All CVEs

CVE-2014-8389

critical · 9.8

cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware LM.1.6.17.01 uses hard-coded credentials in the embedded Boa web server, which allows remote attackers to obtain user credentials via crafted HTTP requests.

9.8
CVSS
50.8%
EPSS (exploit prob.)
99th
EPSS percentile
2017-12-28
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
airlivebu-3026_firmware1.43_21.08.2014
airlivebu-3026all versions
airlivemd-3025_firmware1.81_21.08.2014
airlivemd-3025all versions
airlivewl-2000cam_firmwarelm.1.6.18_14.10.2011
airlivewl-2000camall versions
airlivepoe-200cam_v2_firmwarelm.1.6.17.01
airlivepoe-200cam_v2all versions
airlivebu-2015_firmware1.03.18_16.06.2014
airlivebu-2015all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-8389