9.4
CVSSv2

CVE-2014-8384

Published: 18/05/2015 Updated: 19/05/2015
CVSS v2 Base Score: 9.4 | Impact Score: 9.2 | Exploitability Score: 10
VMScore: 837
Vector: AV:N/AC:L/Au:N/C:N/I:C/A:C

Vulnerability Summary

The InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote malicious users to modify the DHCP server and device IP configuration, reboot the device, change the device name, and have other unspecified impact via a crafted request.

Vulnerable Product Search on Vulmon Subscribe to Product

infocus in3128hd_firmware 0.26

Exploits

Core Security Technologies Advisory - The InFocus IN3128HD Projector is vulnerable to an authentication bypass in its web interface login page, and is missing authentication for the "webctrlcgielf" CGI file, which allows several actions to be performed or configured inside the device Firmware 026 is verified vulnerable ...