Exploitation Summary
EIP tracks 2 public exploits for CVE-2018-10660.
PoCs published by Metasploit, Or Peles, wvu, sinn3r, Brent Cook, Jacob Robles, Matthew Kienow, Shelby Pace, Chris Lee, Cale Black, including Metasploit module exploits/linux/http/axis_srv_parhand_rce.
AI-analyzed exploit summary This Metasploit module exploits an authentication bypass and command injection vulnerability in Axis Network Cameras to achieve remote code execution as root. It leverages the .srv functionality and the parhand service via D-Bus commands.
Description
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
Exploits (2)
This Metasploit module exploits an authentication bypass and command injection vulnerability in Axis Network Cameras to achieve remote code execution as root. It leverages the .srv functionality and the parhand service via D-Bus commands.
This Metasploit module exploits an authentication bypass in Axis Network Camera's .srv functionality and a command injection in parhand to achieve remote code execution as root. It leverages D-Bus communication to inject and execute arbitrary commands.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H