CVE-2014-8329

Schrack Technik Microcontrol Firmware < 1.7.0 - Authentication Bypass

Title source: rule

Description

Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for the ftp and telnet services via a direct request for ZTPUsrDtls.txt.

Scores

EPSS 0.0107
EPSS Percentile 77.5%

Classification

CWE
CWE-287
Status draft

Affected Products (2)

schrack/technik_microcontrol_firmware < 1.7.0
schrack/technik_microcontrol

Timeline

Published Oct 20, 2014
Tracked Since Feb 18, 2026