CVE-2014-3008

Unitrends Enterprise Backup 7.3.0 - Authenticated OS Command Injection via SNMPD Comm Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-3008. PoCs published by Brandon Perry.

AI-analyzed exploit summary This exploit leverages a hardcoded 'auth' parameter and unsanitized SNMP community string input in Unitrends Enterprise Backup 7.3.0 to achieve unauthenticated remote command execution as root via command injection.

Description

Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to recoveryconsole/bpl/snmpd.php.

Exploits (1)

exploitdb WORKING POC
by Brandon Perry · rubyremoteunix
https://www.exploit-db.com/exploits/32885

This exploit leverages a hardcoded 'auth' parameter and unsanitized SNMP community string input in Unitrends Enterprise Backup 7.3.0 to achieve unauthenticated remote command execution as root via command injection.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Unitrends Enterprise Backup 7.3.0
No auth needed
Prerequisites: Network access to the target · SNMP service enabled on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Apr/204
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/92642
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58001
Various Sources x_refsource_misc
https://gist.github.com/brandonprry/10745756
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/66928
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/32885

Scores

EPSS 0.0696
EPSS Percentile 93.3%

Details

CWE
CWE-78
Status published
Products (1)
unitrends/enterprise_backup 7.3.0
Published Apr 28, 2014
Tracked Since Feb 18, 2026