CVE-2014-7999: Cisco Meraki Mr

High severity, CVSS 7.7. EPSS: 0.7% chance of exploitation in the next 30 days.

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote authenticated users to install arbitrary firmware by leveraging unspecified HTTP handler access on the local network, aka Cisco-Meraki defect ID 00478565.

Affected products

  • Cisco Meraki Mr
  • Cisco Meraki Mr Firmware: up to and including 2014-09-24
  • Cisco Meraki Ms
  • Cisco Meraki Ms Firmware: up to and including 2014-09-24
  • Cisco Meraki Mx
  • Cisco Meraki Mx Firmware: up to and including 2014-09-24

Published 2014-12-24. Last modified 2026-06-17.