CVE-2014-7994: Cisco Meraki Mr

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote attackers to execute arbitrary commands by leveraging knowledge of a cross-device secret and a per-device secret, and sending a request to an unspecified HTTP handler on the local network, aka Cisco-Meraki defect ID 00301991.

Affected products

  • Cisco Meraki Mr
  • Cisco Meraki Mr Firmware: up to and including 2014-09-24
  • Cisco Meraki Ms
  • Cisco Meraki Ms Firmware: up to and including 2014-09-24
  • Cisco Meraki Mx
  • Cisco Meraki Mx Firmware: up to and including 2014-09-24

Published 2014-12-24. Last modified 2026-06-17.