AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2014-1406

MEDIUM · CVSS 4.3 EPSS 0.98%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-01-10 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2014-1406
Severity
MEDIUM
CVSS
4.3
EPSS
0.98%

Original Filing — NVD Description

CRLF injection vulnerability in goform/formWlSiteSurvey on the Conceptronic C54APM access point with runtime code 1.26 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the submit-url parameter in a Refresh action.