← Vulnerability feed

Vulnerability record · CVE-2014-8424 · published 28 November 2014

CVE-2014-8424: ARRIS VAP2500 firmware improper password validation allows auth bypass

Arris · Vap2500 Firmware

ARRIS VAP2500 firmware before FW08.41 does not properly validate passwords, allowing remote attackers to bypass authentication. Because the flaw is in authentication logic rather than a memory-safety bug, a successful bypass grants access to the device without valid credentials. The record does not specify which interfaces or accounts are affected beyond the authentication bypass itself.

7.8 CVSS 2.0 High EPSS 60% · top 0.9% CWE-287 · Improper authentication
7.8CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.

AV:N/AC:L/Au:N/C:C/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote authentication bypass with full confidentiality impact and a very high EPSS percentile, though no confirmed in-the-wild exploitation is documented in this record.

What it is

ARRIS VAP2500 firmware before FW08.41 does not properly validate passwords, allowing remote attackers to bypass authentication. Because the flaw is in authentication logic rather than a memory-safety bug, a successful bypass grants access to the device without valid credentials. The record does not specify which interfaces or accounts are affected beyond the authentication bypass itself.

Impact

An unauthenticated remote attacker gains access to the device's protected functionality, with the CVSS vector indicating a full confidentiality impact (C:C) and no integrity or availability impact. In practice this exposes configuration and data reachable through the bypassed authentication layer.

Attack surface

Reachable over the network (AV:N) with low attack complexity (AC:L) and no authentication required (Au:N), per the CVSS 2.0 vector. The description does not state whether user interaction is needed, but the vector implies none.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.59617, 99th percentile), suggesting elevated likelihood of exploitation activity, but the references carry no exploit tags and no public exploit is confirmed by this record.

What to do

  • Upgrade VAP2500 firmware to FW08.41 or later, which the description identifies as the fixed version.
  • If the device cannot be updated, restrict management and service interfaces to trusted networks and block exposure to the internet.
  • Replace or isolate end-of-life VAP2500 units that cannot receive the fixed firmware.
  • Enforce strong unique credentials and monitor authentication logs for anomalous successful logins.
  • Segment the device on a dedicated VLAN with strict firewall rules limiting inbound access.

Detection

  • Monitor authentication logs for successful logins from unexpected source IPs or with malformed or empty password fields.
  • Alert on management interface access from external or non-management networks.
  • Baseline normal VAP2500 traffic and flag unusual sessions or configuration changes following authentication events.
  • Watch for repeated authentication attempts or bypass patterns against the device's web or management services.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-8424 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-8423ARRIS VAP2500 management portal command injectionThe management portal in ARRIS VAP2500 firmware before FW08.41 contains an unspecified injection flaw (CWE-74) that allows remote attackers to execut…EPSS 62%analysed7.8CVE-2014-8425Arris vap2500 firmware information exposure vulnerabilityThe management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.EPSS 3.1%5.1CVE-2024-5196Arris vap2500 firmware command injection vulnerabilityA vulnerability classified as critical has been found in Arris VAP2500 08.50. This affects an unknown part of the file /tools_command.php. The manipu…EPSS 23%5.1CVE-2024-5195Arris vap2500 firmware command injection vulnerabilityA vulnerability was found in Arris VAP2500 08.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file /di…EPSS 23%5.1CVE-2024-5194Arris vap2500 firmware command injection vulnerabilityA vulnerability was found in Arris VAP2500 08.50. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the…EPSS 3.6%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed

Source: NIST National Vulnerability Database (record CVE-2014-8424), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.