CVE-2017-7462

CRITICAL

Intellinet NFC-30ir IP Camera - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-7462. PoCs published by Dimitri Fousekis.

AI-analyzed exploit summary The advisory describes two vulnerabilities in Intellinet NFC-30IR Network Cameras: an authenticated Local File Inclusion (LFI) via '/cgi-bin/admin/fileread' and a hard-coded manufacturer backdoor accessible via '/cgi-bin/mft/manufacture' with credentials 'manufacture:erutcafunam'.

Description

Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.

Exploits (1)

exploitdb WRITEUP
by Dimitri Fousekis · textwebappshardware
https://www.exploit-db.com/exploits/41829

The advisory describes two vulnerabilities in Intellinet NFC-30IR Network Cameras: an authenticated Local File Inclusion (LFI) via '/cgi-bin/admin/fileread' and a hard-coded manufacturer backdoor accessible via '/cgi-bin/mft/manufacture' with credentials 'manufacture:erutcafunam'.

Classification
Writeup 100%
Attack Type
Info Leak | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Intellinet NFC-30IR Network Cameras with firmware version LM.1.6.16.05
Auth required
Prerequisites: Network access to the camera · Valid admin credentials for LFI · Knowledge of hard-coded credentials for backdoor
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41829/

Scores

CVSS v3 9.8
EPSS 0.1275
EPSS Percentile 95.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22 CWE-798
Status published
Products (1)
intellinet-network/nfc-30ir_firmware lm.1.6.16.05
Published Apr 11, 2017
Tracked Since Feb 18, 2026