CVE-2014-1406
EUVD-2014-148310.01.2014, 16:47
CRLF injection vulnerability in goform/formWlSiteSurvey on the Conceptronic C54APM access point with runtime code 1.26 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the submit-url parameter in a Refresh action.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| conceptronic | c54apm_firmware | 1.26 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration