CVE-2014-0121: hawtio-karaf-terminal: remote code execution due to missing authentication

Severity: Critical

CVSS Score: 9.8

The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.