CVE-2017-14743

HIGH

Faleemi FSC-880 00.01.01.0048P2 - Unauthenticated SQL Injection via Username Element in ONVIF Device Service

Title source: llm
STIX 2.1

Description

Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password.

References (1)

Core 1
Core References

Scores

CVSS v3 8.1
EPSS 0.0122
EPSS Percentile 65.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
faleemi/fsc-880_firmware 00.01.01.0048p2
Published Sep 26, 2017
Tracked Since Feb 18, 2026