CVE-2013-3686
AirLive WL2600CAM - Information Disclosure via CGI Operator Param
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-3686.
AI-analyzed exploit summary This document provides a detailed technical analysis of multiple vulnerabilities in Airlive devices, including CSRF, path traversal, information exposure, and DoS. It includes PoC URLs and a Python script for testing the DoS vulnerability.
Description
cgi-bin/operator/param in AirLive WL2600CAM and possibly other camera models allows remote attackers to obtain the administrator password via a list action.
Exploits (1)
exploitdb
WRITEUP
webappshardware
https://www.exploit-db.com/exploits/26174
This document provides a detailed technical analysis of multiple vulnerabilities in Airlive devices, including CSRF, path traversal, information exposure, and DoS. It includes PoC URLs and a Python script for testing the DoS vulnerability.
Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target:
Airlive WL2600CAM, POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD
No auth needed
Prerequisites:
Network access to the vulnerable device
MITRE ATT&CK
devstral-2 · analyzed Feb 19, 2026
Full analysis →
References (1)
Core 1
Core References
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2013/Jun/84
Scores
EPSS
0.2757
EPSS Percentile
97.8%
Details
CWE
CWE-264
Status
published
Products (1)
ovislink/airlive_wl2600cam
Published
Oct 11, 2013
Tracked Since
Feb 18, 2026