nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-18377 CVE-2017-18377
CRITICAL
goahead wireless_ip_camera_wificam_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2017-18377 has a selected CVSS score of 9.8 (critical).
Description
An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cgi?svr=192.168.1.1&port=21&user=ftp URI.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 13, 2019 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wireless_ip_camera_wificam_firmwareBrowse goahead / wireless_ip_camera_wificam_firmware | VulnCheck | Version data not supplied | |
References
2pierrekim.github.io
https://pierrekim.github.io/blog/2017-03-08-camera-goahead-0day.html