CVE-2014-8387
Advantech EKI-6340 2.05 - Authenticated OS Command Injection via pinghost Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-8387. PoCs published by Core Security.
AI-analyzed exploit summary The exploit demonstrates an OS command injection vulnerability in Advantech EKI-6340 via the 'ping.cgi' file, allowing remote attackers to execute arbitrary commands by injecting them after the 'pinghost' parameter. Authentication is required but can be bypassed using default credentials (user:user).
Description
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.
Exploits (1)
The exploit demonstrates an OS command injection vulnerability in Advantech EKI-6340 via the 'ping.cgi' file, allowing remote attackers to execute arbitrary commands by injecting them after the 'pinghost' parameter. Authentication is required but can be bypassed using default credentials (user:user).