CVE-2017-8223
HIGH EXPLOITED IN THE WILDWireless IP Camera (P2P) WIFICAM - Unauthenticated RTSP Stream Access via Port 10554
Title source: llmExploitation Summary
CVE-2017-8223 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit.
AI-analyzed exploit summary This exploit targets a command injection vulnerability in the GoAhead web server used in various IP cameras. It bypasses authentication to extract credentials, then injects a reverse shell payload via the FTP configuration CGI endpoints.
Description
On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via tcp/av0_1 or tcp/av0_0.
Exploits (1)
This exploit targets a command injection vulnerability in the GoAhead web server used in various IP cameras. It bypasses authentication to extract credentials, then injects a reverse shell payload via the FTP configuration CGI endpoints.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N