CVE-2014-8868 EXPLOIT
7.8
HIGH · CVSS 2.0 · EPSS 7% (pctl 94)
Patch early
A public exploit exists.
Description
EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username and password, and possibly other sensitive information, via a request to /4.
Scoring
| CVSS | 7.8 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
| EPSS | 6.99% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-12-07 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| entrypass | n5200 active network control panel |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | EntryPass N5200 - Credentials Exposure | 2014-12-02 |
References
- http://seclists.org/fulldisclosure/2014/Dec/2
- http://www.securityfocus.com/archive/1/534128/100/0/threaded
- https://www.redteam-pentesting.de/advisories/rt-sa-2014-011
- http://seclists.org/fulldisclosure/2014/Dec/2
- http://www.securityfocus.com/archive/1/534128/100/0/threaded
- https://www.redteam-pentesting.de/advisories/rt-sa-2014-011
→ the Explorer · watch your stack · NVD