Airlive manufactures a narrow line of wireless networking appliances, specifically bridge and access-point products such as the BU-2015 and BU-3026 series, that operate in embedded environments. The vendor's vulnerability disclosures center on OS command-injection issues endemic to firmware that processes user-supplied input for network configuration, a pattern characteristic of devices with limited input validation in embedded code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Airlive over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8389CRITICAL cgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive MD-3025 with firmware 1.81 21.08.2014, AirL | Dec 28, 2017 | 9.8 | 53 | NO | NO |
CVE-2015-2279CRITICAL cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows remote attackers to execute arbitrary OS commands via shell | Jul 25, 2017 | 9.8 | 43 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Airlive.
Media articles that mention a CVE ID that affects a product developed by Airlive — matched by CVE ID, not by vendor name.