CVE-2013-3686

AirLive WL2600CAM - Information Disclosure via CGI Operator Param

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-3686.

AI-analyzed exploit summary This document provides a detailed technical analysis of multiple vulnerabilities in Airlive devices, including CSRF, path traversal, information exposure, and DoS. It includes PoC URLs and a Python script for testing the DoS vulnerability.

Description

cgi-bin/operator/param in AirLive WL2600CAM and possibly other camera models allows remote attackers to obtain the administrator password via a list action.

Exploits (1)

exploitdb WRITEUP
webappshardware
https://www.exploit-db.com/exploits/26174

This document provides a detailed technical analysis of multiple vulnerabilities in Airlive devices, including CSRF, path traversal, information exposure, and DoS. It includes PoC URLs and a Python script for testing the DoS vulnerability.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Airlive WL2600CAM, POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD
No auth needed
Prerequisites: Network access to the vulnerable device
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2013/Jun/84

Scores

EPSS 0.2757
EPSS Percentile 97.8%

Details

CWE
CWE-264
Status published
Products (1)
ovislink/airlive_wl2600cam
Published Oct 11, 2013
Tracked Since Feb 18, 2026