CVE-2017-5173

CRITICAL EXPLOITED IN THE WILD

Geutebruck IP Camera G-Cam/EFD-2250 <1.11.0.12 - Command Injection

Title source: llm

Description

An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not properly neutralized, an attacker can call multiple parameters that can allow access to the root level operating system which could allow remote code execution.

Exploits (1)

exploitdb WORKING POC VERIFIED
by RandoriSec · rubywebappshardware
https://www.exploit-db.com/exploits/41360

Scores

CVSS v3 9.8
EPSS 0.8483
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2019-06-13
InTheWild.io 2017-02-15
CWE
CWE-78
Status published
Products (2)
geutebrueck/ip_camera_g-cam_efd-2250_firmware 1.11.0.12
n/a/Geutebruck IP Cameras Geutebruck IP Cameras
Published May 19, 2017
Tracked Since Feb 18, 2026