← Vulnerability feed

Vulnerability record · CVE-2014-8423 · published 28 November 2014

CVE-2014-8423: ARRIS VAP2500 management portal command injection

Arris · Vap2500 Firmware

The management portal in ARRIS VAP2500 firmware before FW08.41 contains an unspecified injection flaw (CWE-74) that allows remote attackers to execute arbitrary commands. The vulnerability is network-reachable and requires no authentication, making it a severe pre-auth remote code execution issue for exposed devices.

10.0 CVSS 2.0 High EPSS 62% · top 0.8% CWE-74 · Injection
10.0CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityUnauthenticated remote command execution with maximum CVSS impact and high EPSS probability makes this an urgent patching priority.

What it is

The management portal in ARRIS VAP2500 firmware before FW08.41 contains an unspecified injection flaw (CWE-74) that allows remote attackers to execute arbitrary commands. The vulnerability is network-reachable and requires no authentication, making it a severe pre-auth remote code execution issue for exposed devices.

Impact

An unauthenticated remote attacker can execute arbitrary commands on the device, gaining full control of confidentiality, integrity, and availability. This could allow the device to be used as a pivot point or botnet node.

Attack surface

The flaw is in the management portal, reachable over the network (AV:N) with no authentication (Au:N) and no user interaction. Any internet- or network-exposed management interface on affected firmware is a potential entry point.

Exploitation

The CVE is not listed in CISA KEV, but EPSS indicates a high probability of exploitation (0.62476, 99th percentile). The ZDI advisory reference suggests coordinated disclosure, but no public exploit details are provided in the record.

What to do

  • Upgrade ARRIS VAP2500 firmware to FW08.41 or later immediately.
  • Restrict access to the management portal to trusted networks or VPN only; never expose it to the internet.
  • Disable remote management if not required, or place it behind a firewall with strict IP allowlisting.
  • Monitor for vendor patches or updated advisories and apply them as they become available.
  • Segment affected devices on isolated VLANs to limit lateral movement if compromised.

Detection

  • Monitor management portal logs for unusual command execution attempts or unexpected process creation.
  • Use network IDS/IPS signatures to detect injection patterns targeting the management interface.
  • Audit exposed management portals for unauthorized access or configuration changes.
  • Check device firmware versions against the fixed FW08.41 baseline.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-8423 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2014-8425Arris vap2500 firmware information exposure vulnerabilityThe management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.EPSS 3.1%7.8CVE-2014-8424ARRIS VAP2500 firmware improper password validation allows auth bypassARRIS VAP2500 firmware before FW08.41 does not properly validate passwords, allowing remote attackers to bypass authentication. Because the flaw is i…EPSS 60%analysed5.1CVE-2024-5196Arris vap2500 firmware command injection vulnerabilityA vulnerability classified as critical has been found in Arris VAP2500 08.50. This affects an unknown part of the file /tools_command.php. The manipu…EPSS 23%5.1CVE-2024-5195Arris vap2500 firmware command injection vulnerabilityA vulnerability was found in Arris VAP2500 08.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file /di…EPSS 23%5.1CVE-2024-5194Arris vap2500 firmware command injection vulnerabilityA vulnerability was found in Arris VAP2500 08.50. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the…EPSS 3.6%10.0CVE-2025-20337Cisco ISE API input validation flaw allows unauthenticated root RCECisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, letting an unauthenticated remote attacker execute arbitrary c…KEVEPSS 68%analysed10.0CVE-2025-20281Cisco ISE API unauthenticated remote code executionCisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, allowing a crafted request to reach the underlying operating s…KEVEPSS 98%analysed7.2CVE-2022-43769Hitachi Vantara Pentaho BA Server Spring Template InjectionHitachi Vantara Pentaho Business Analytics Server before 9.4.0.1 and 9.3.0.2, including 8.3.x, allows certain web services to set property values con…KEVEPSS 98%analysed

Source: NIST National Vulnerability Database (record CVE-2014-8423), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.