CVE Feed

    Dashboard / CVE / CVE-2014-8389

    CVE-2014-8389

    cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware LM.1.6.17.01 uses hard-coded credentials in the embedded Boa web server, which allows remote attackers to obtain user credentials via crafted HTTP requests.

    Published:Dec 27, 2017
    Last Modified:Apr 20, 2025
    EPS:Dec 27, 2017
    EPSS Score:0.14008
    CVSS Score:9.8

    Affected Products

    Vendor
    Airlive
    Product
    Bu-2015
    Vendor
    Airlive
    Product
    Bu-2015 Firmware
    Vendor
    Airlive
    Product
    Bu-3026
    Vendor
    Airlive
    Product
    Bu-3026 Firmware
    Vendor
    Airlive
    Product
    Md-3025
    Vendor
    Airlive
    Product
    Md-3025 Firmware
    Vendor
    Airlive
    Product
    Poe-200cam V2
    Vendor
    Airlive
    Product
    Poe-200cam V2 Firmware
    Vendor
    Airlive
    Product
    Wl-2000cam
    Vendor
    Airlive
    Product
    Wl-2000cam Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High