Record summary

CVE-2017-17105 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a cgi-bin/iptest.cgi?cmd=iptest.cgi&-time="1504225666237"&-url=$(reboot) request.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 21, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

MetasploitZivif Camera iptest.cgi Blind Remote Command ExecutionMetasploit exploitby Silas Cutler (p1nk)Not analyzed1 file

Ruby

Metasploit

PoC details

References

5