CVE-2014-2595

CRITICAL

Barracuda WAF 7.8.1.013 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-2595. PoCs published by Nick Hayes.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in Barracuda Web Application Firewall by manipulating URL parameters to gain unauthorized access. The PoC provides a crafted URL that bypasses authentication by setting specific parameters.

Description

Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Nick Hayes · textremotehardware
https://www.exploit-db.com/exploits/39278

This exploit demonstrates an authentication bypass vulnerability in Barracuda Web Application Firewall by manipulating URL parameters to gain unauthorized access. The PoC provides a crafted URL that bypasses authentication by setting specific parameters.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Barracuda Web Application Firewall 7.8.1.013
No auth needed
Prerequisites: Network access to the target appliance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/127740/Barracuda-WAF-Authentication-Bypass.html
Exploit, Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/fulldisclosure/2014/Aug/5
Broken Link x_refsource_misc
http://www.osvdb.org/109782
Exploit, Third Party Advisory x_refsource_misc
https://vulners.com/securityvulns/SECURITYVULNS:DOC:31004
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.securityfocus.com/bid/69028
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/39278

Scores

CVSS v3 9.8
EPSS 0.5747
EPSS Percentile 98.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-613
Status published
Products (1)
barracuda/web_application_firewall 7.8.1.013
Published Feb 12, 2020
Tracked Since Feb 18, 2026