CVE-2014-0121: Hawt Hawtio

Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.

The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.

Affected products

  • Hawt Hawtio: up to and including 1.2.2
  • Red Hat JBoss Fuse: version 6.1.0 only

Published 2017-12-29. Last modified 2026-06-17.