Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-7462. PoCs published by Dimitri Fousekis.
AI-analyzed exploit summary The advisory describes two vulnerabilities in Intellinet NFC-30IR Network Cameras: an authenticated Local File Inclusion (LFI) via '/cgi-bin/admin/fileread' and a hard-coded manufacturer backdoor accessible via '/cgi-bin/mft/manufacture' with credentials 'manufacture:erutcafunam'.
Description
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.
Exploits (1)
The advisory describes two vulnerabilities in Intellinet NFC-30IR Network Cameras: an authenticated Local File Inclusion (LFI) via '/cgi-bin/admin/fileread' and a hard-coded manufacturer backdoor accessible via '/cgi-bin/mft/manufacture' with credentials 'manufacture:erutcafunam'.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H