CVE-2014-8389 Details
Description
cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware LM.1.6.17.01 uses hard-coded credentials in the embedded Boa web server, which allows remote attackers to obtain user credentials via crafted HTTP requests.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| airlive bu-3026 firmware | 1.43_21.08.2014 |
CPE
Remediation
| |
| airlive bu-3026 | All versions |
CPE
Remediation
| |
| airlive md-3025 firmware | 1.81_21.08.2014 |
CPE
Remediation
| |
| airlive md-3025 | All versions |
CPE
Remediation
| |
| airlive wl-2000cam firmware | lm.1.6.18_14.10.2011 |
CPE
Remediation
| |
| airlive wl-2000cam | All versions |
CPE
Remediation
| |
| airlive poe-200cam v2 firmware | lm.1.6.17.01 |
CPE
Remediation
| |
| airlive poe-200cam v2 | All versions |
CPE
Remediation
| |
| airlive bu-2015 firmware | 1.03.18_16.06.2014 |
CPE
Remediation
| |
| airlive bu-2015 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 9, 2018 | CVE Modified | [email protected] |
| Jan 12, 2018 | Initial Analysis | [email protected] |