CVE-2014-8684

CRITICAL

CodeIgniter <3.0 & Kohana 3.2.3-3.3.2 - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-8684. Includes Metasploit module exploits/linux/http/seagate_nas_php_exec_noauth.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated remote command execution vulnerability in Seagate Business NAS devices via a local file inclusion flaw in the CodeIgniter session cookie's language parameter. It decrypts the session cookie, modifies it to gain admin privileges, and injects a PHP payload to achieve RCE.

Description

CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.

Exploits (2)

metasploit WORKING POC NORMAL
rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/seagate_nas_php_exec_noauth.rb

This Metasploit module exploits an unauthenticated remote command execution vulnerability in Seagate Business NAS devices via a local file inclusion flaw in the CodeIgniter session cookie's language parameter. It decrypts the session cookie, modifies it to gain admin privileges, and injects a PHP payload to achieve RCE.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Seagate Business NAS (STBN300 and others)
No auth needed
Prerequisites: Network access to the target device · PHP and CodeIgniter session cookie manipulation
devstral-2 · analyzed Apr 23, 2026 Full analysis →
exploitdb WORKING POC
rubyremotephp
https://www.exploit-db.com/exploits/36264

This Metasploit module exploits an unauthenticated remote command execution vulnerability in Seagate Business NAS devices via a local file inclusion flaw in the CodeIgniter session cookie's language parameter. It decrypts the session cookie, modifies it to gain admin privileges, and uploads a PHP payload to achieve RCE.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Seagate Business NAS (STBN300)
No auth needed
Prerequisites: Network access to the target device · Target device must be vulnerable (CVE-2014-8684)
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (4)

Core 4
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/May/54
Third Party Advisory x_refsource_confirm
https://github.com/kohana/core/pull/492

Scores

CVSS v3 9.8
EPSS 0.4485
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-310
Status published
Products (6)
codeigniter/codeigniter < 2.2.6
codeigniter/framework 0 - 3.0.0Packagist
kohana/core 0 - 3.3.3Packagist
kohanaframework/kohana 3.2.3
kohanaframework/kohana 3.3.0
kohanaframework/kohana 3.3.1
Published Sep 19, 2017
Tracked Since Feb 18, 2026