The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors involving JavaScript.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-2410 The web server on the AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to bypass authentication and modify settings via a direct request to an unspecified URL.
Fixes

Solution

Accuenergy has produced a patch to mitigate these vulnerabilities. The patch can be downloaded at the following location:  http://www.accuenergy.com/firmware-update-axm-net


Workaround

No workaround given by the vendor.

History

Mon, 13 Oct 2025 23:00:00 +0000

Type Values Removed Values Added
Description The web server on the AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to bypass authentication and modify settings via a direct request to an unspecified URL. The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors involving JavaScript.
Title Accuenergy Accuenergy Acuvim II Authentication Bypass Issues Accuenergy Accuenergy Acuvim II Client-Side Enforcement of Server-Side Security
Weaknesses CWE-592 CWE-602

Mon, 13 Oct 2025 22:45:00 +0000

Type Values Removed Values Added
Title Accuenergy Accuenergy Acuvim II Authentication Bypass Issues
Weaknesses CWE-592
References

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-10-13T22:39:34.813Z

Reserved: 2014-03-13T00:00:00

Link: CVE-2014-2373

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-11-05T11:55:04.637

Modified: 2025-10-13T23:15:34.490

Link: CVE-2014-2373

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.