CVE-2017-5173

CRITICAL EXPLOITED IN THE WILD

Geutebruck IP Camera G-Cam/EFD-2250 <1.11.0.12 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2017-5173 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including RandoriSec.

AI-analyzed exploit summary This Metasploit module exploits an authentication bypass (CVE-2017-5174) and command injection (CVE-2017-5173) in Geutebruck's testaction.cgi, allowing unauthenticated RCE with root privileges via a crafted POST request.

Description

An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not properly neutralized, an attacker can call multiple parameters that can allow access to the root level operating system which could allow remote code execution.

Exploits (1)

exploitdb WORKING POC VERIFIED
by RandoriSec · rubywebappshardware
https://www.exploit-db.com/exploits/41360

This Metasploit module exploits an authentication bypass (CVE-2017-5174) and command injection (CVE-2017-5173) in Geutebruck's testaction.cgi, allowing unauthenticated RCE with root privileges via a crafted POST request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Geutebruck G-Cam/EFD-2250 firmware <= 1.11.0.12
No auth needed
Prerequisites: Network access to the target device · Vulnerable firmware version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96209
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-045-02
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41360/

Scores

CVSS v3 9.8
EPSS 0.2958
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2019-06-13
InTheWild.io 2017-02-15
CWE
CWE-78
Status published
Products (2)
geutebrueck/ip_camera_g-cam_efd-2250_firmware 1.11.0.12
n/a/Geutebruck IP Cameras Geutebruck IP Cameras
Published May 19, 2017
Tracked Since Feb 18, 2026