CVE-2013-3540

AirLive OD-2025HD OD-2060HD POE100HD POE200HD POE250HD POE2600HD - Cross-Site Request Forgery in User Group Management

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-3540.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Airlive devices, including CSRF, path traversal, information exposure, and DoS. It provides functional PoC URLs and a Python script for testing the DoS vulnerability.

Description

Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/usrgrp.cgi in AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.

Exploits (1)

exploitdb WORKING POC
webappshardware
https://www.exploit-db.com/exploits/26174

The exploit demonstrates multiple vulnerabilities in Airlive devices, including CSRF, path traversal, information exposure, and DoS. It provides functional PoC URLs and a Python script for testing the DoS vulnerability.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Airlive WL2600CAM, POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD
No auth needed
Prerequisites: Network access to the target device
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2013/Jun/84

Scores

EPSS 0.0101
EPSS Percentile 58.8%

Details

CWE
CWE-352
Status published
Products (6)
ovislink/airlive_od-2025hd
ovislink/airlive_od-2060hd
ovislink/airlive_poe100hd
ovislink/airlive_poe200hd
ovislink/airlive_poe250hd
ovislink/airlive_poe2600hd
Published Oct 04, 2013
Tracked Since Feb 18, 2026