CVE-2017-14003: Lavalink Ether-Serial Link Firmware

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by accessing a specific uniform resource locator.

Affected products

  • Lavalink Ether-Serial Link Firmware: up to and including 6.01.00\/29.03.2007

Published 2017-10-11. Last modified 2026-06-17.