CVE-2014-1408
high
CVSS v3
—
CVSS v2
7.8
VIR risk
7.8
Description
The Conceptronic C54APM access point with runtime code 1.26 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via an HTTP request, as demonstrated by stored XSS attacks.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://antoniovazquezblanco.github.io/docs/advisories/Advisory_C54APM_Multiple.pdf
References
- http://antoniovazquezblanco.github.io/docs/advisories/Advisory_C54APM_Multiple.pdf
- http://download.conceptronic.net/manuals/C04-058_C54APM_v2.0_Quick_Guide_ML.pdf
- http://antoniovazquezblanco.github.io/docs/advisories/Advisory_C54APM_Multiple.pdf
- http://download.conceptronic.net/manuals/C04-058_C54APM_v2.0_Quick_Guide_ML.pdf
CWEs
CWE-255
Verify integrity in audit chain (admin only). AS-IS.