AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2014-2846

HIGH · CVSS 7.5 EPSS 8.83%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-04-28 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable.

CVE
CVE-2014-2846
Severity
HIGH
CVSS
7.5
EPSS
8.83%

Original NVD Description

Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin.