← Vulnerability feed

Vulnerability record · CVE-2014-9614 · published 19 February 2020

CVE-2014-9614: Netsweeper Web Panel hard-coded branding account password

Netsweeper · Netsweeper

The Netsweeper Web Panel before 4.0.5 ships with a default password of 'branding' for the branding account. Anyone who can reach the webadmin/ interface can log in with these known credentials and gain administrative access to the panel.

9.8 CVSS 3.1 Critical EPSS 69% · top 0.7% CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score, v2 7.5
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityA remotely reachable, unauthenticated default credential with a CVSS score of 9.8 and very high EPSS probability gives attackers full panel access with minimal effort.

What it is

The Netsweeper Web Panel before 4.0.5 ships with a default password of 'branding' for the branding account. Anyone who can reach the webadmin/ interface can log in with these known credentials and gain administrative access to the panel.

Impact

An attacker gains authenticated access to the Netsweeper Web Panel with the privileges of the branding account, which the CVSS vector rates as high for confidentiality, integrity and availability.

Attack surface

Reachable remotely over the network via a request to webadmin/ with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS is 0.687 (99.3rd percentile), indicating a high modeled likelihood of exploitation, and the only references are third-party advisories with no exploit tag.

What to do

  • Upgrade Netsweeper to 4.0.5 or later, which removes the default branding password.
  • If upgrade is not immediate, change the branding account password and disable or rename the account if it is unused.
  • Restrict network access to the webadmin/ interface to trusted management networks only.
  • Audit for any other default or hard-coded accounts in the Web Panel and rotate their credentials.

Detection

  • Search Web Panel authentication logs for successful logins to the branding account, especially from unexpected source IPs.
  • Alert on any authentication to webadmin/ using the password 'branding' or other known default credentials.
  • Monitor for first-time or anomalous access to the webadmin/ path from external or non-management networks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-9614 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-3859Netsweeper vulnerabilityUnspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-2012-2446 an…EPSS 2.9%9.8CVE-2020-13167Netsweeper unauthenticated OS command injection in unixlogin.phpNetsweeper through 6.4.3 contains an OS command injection flaw in webadmin/tools/unixlogin.php. The script launches a command line using client-suppl…EPSS 95%analysed9.8CVE-2014-9612Netsweeper sql injection vulnerabilitySQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote…EPSS 4.9%9.8CVE-2014-9613Netsweeper sql injection vulnerabilityMultiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login para…EPSS 4.1%9.8CVE-2014-9611Netsweeper improper authentication vulnerabilityNetsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/i…EPSS 13%9.8CVE-2014-9618Netsweeper Client Filter Admin authentication bypass via showdeny actionThe Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 fails to properly enforce authentication. A re…EPSS 73%analysed9.4CVE-2014-9605Netsweeper improper authentication vulnerabilityWebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a syst…EPSS 3.9%7.5CVE-2014-9616Netsweeper information exposure vulnerabilityNetsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a request that…EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2014-9614), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.