A remote unauthenticated attacker may execute commands as root by sending an unauthenticated crafted POST request to the httpd that serves authentication on the guest login network.
more here.........https://labs.integrity.pt/advisories/cve-2014-1635/
more here.........https://labs.integrity.pt/advisories/cve-2014-1635/