CVE-2017-5174

CRITICAL EXPLOITED IN THE WILD

Geutebruck IP Camera G-Cam/EFD-2250 <1.11.0.12 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2017-5174 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including RandoriSec.

AI-analyzed exploit summary This Metasploit module exploits an authentication bypass (CVE-2017-5174) and command injection (CVE-2017-5173) in Geutebruck's testaction.cgi, allowing unauthenticated RCE with root privileges via a crafted POST request.

Description

An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has been identified. The existing file system architecture could allow attackers to bypass the access control that may allow remote code execution.

Exploits (1)

exploitdb WORKING POC VERIFIED
by RandoriSec · rubywebappshardware
https://www.exploit-db.com/exploits/41360

This Metasploit module exploits an authentication bypass (CVE-2017-5174) and command injection (CVE-2017-5173) in Geutebruck's testaction.cgi, allowing unauthenticated RCE with root privileges via a crafted POST request.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Geutebruck G-Cam/EFD-2250 firmware <= 1.11.0.12
No auth needed
Prerequisites: Network access to the target device · Vulnerable firmware version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96209
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-17-045-02
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41360/

Scores

CVSS v3 9.8
EPSS 0.5229
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2019-06-06
InTheWild.io 2019-12-13
CWE
CWE-288
Status published
Products (2)
geutebruck/ip_camera_g-cam_efd-2250_firmware 1.11.0.12
n/a/Geutebruck IP Cameras Geutebruck IP Cameras
Published May 19, 2017
Tracked Since Feb 18, 2026