CVE-2017-5173
CRITICAL EXPLOITED IN THE WILDGeutebruck IP Camera G-Cam/EFD-2250 <1.11.0.12 - Command Injection
Title source: llmExploitation Summary
CVE-2017-5173 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including RandoriSec.
AI-analyzed exploit summary This Metasploit module exploits an authentication bypass (CVE-2017-5174) and command injection (CVE-2017-5173) in Geutebruck's testaction.cgi, allowing unauthenticated RCE with root privileges via a crafted POST request.
Description
An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not properly neutralized, an attacker can call multiple parameters that can allow access to the root level operating system which could allow remote code execution.
Exploits (1)
This Metasploit module exploits an authentication bypass (CVE-2017-5174) and command injection (CVE-2017-5173) in Geutebruck's testaction.cgi, allowing unauthenticated RCE with root privileges via a crafted POST request.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H