Vulnerability record · CVE-2014-8389 · published 28 December 2017
CVE-2014-8389: AirLive IP cameras hard-coded credentials in Boa web server
Airlive · Bu 3026 Firmware
Multiple AirLive camera and firmware models ship a Boa web server with hard-coded credentials, and the wireless_mft.cgi endpoint exposes them. The record's CWE (OS command injection) does not match the description, which describes credential disclosure, so the flaw class is inconsistent in the source data. It matters because the affected devices are network-facing and the credentials can be retrieved without authentication.
Description
cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirLive WL-2000CAM with firmware LM.1.6.18 14.10.2011, and AirLive POE-200CAM v2 with firmware LM.1.6.17.01 uses hard-coded credentials in the embedded Boa web server, which allows remote attackers to obtain user credentials via crafted HTTP requests.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityUnauthenticated remote credential disclosure on internet-facing cameras with public exploit references and very high EPSS, though not in KEV and with no confirmed fixed firmware in the record.
What it is
Multiple AirLive camera and firmware models ship a Boa web server with hard-coded credentials, and the wireless_mft.cgi endpoint exposes them. The record's CWE (OS command injection) does not match the description, which describes credential disclosure, so the flaw class is inconsistent in the source data. It matters because the affected devices are network-facing and the credentials can be retrieved without authentication.
Impact
A remote attacker can obtain user credentials for the device, giving access to the camera's web interface and any functions those credentials authorize. The CVSS 3.0 vector claims high confidentiality, integrity and availability impact, but the description only supports credential disclosure.
Attack surface
Reached over the network via crafted HTTP requests to cgi-bin/mft/wireless_mft.cgi on the embedded Boa web server. The CVSS vector indicates no privileges and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.50772 (98.9th percentile) and multiple references are tagged Exploit, so public exploit material exists.
What to do
- Apply vendor firmware updates for the listed AirLive models if any are still available; the record does not state a fixed version.
- If no patch exists, isolate affected cameras on a segmented VLAN with no internet exposure and restrict management access to trusted hosts.
- Replace end-of-life AirLive BU-2015, BU-3026, MD-3025, WL-2000CAM and POE-200CAM v2 devices that no longer receive firmware.
- Block or monitor external access to cgi-bin/mft/wireless_mft.cgi at the perimeter and reverse proxy.
- Rotate any credentials used on these devices and audit for reuse elsewhere.
Detection
- Search web or proxy logs for requests to /cgi-bin/mft/wireless_mft.cgi, especially from unexpected source addresses.
- Alert on HTTP responses from these cameras that contain credential-like fields or unusually large bodies.
- Inventory the network for the affected AirLive models and firmware versions and flag any that are internet-reachable.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-8389 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-8389), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.