CVE-2018-10662
CRITICAL IN THE WILDAxis IP Cameras - Exposed Insecure Interface
Title source: llmExploitation Summary
CVE-2018-10662 has been observed exploited in the wild (reported by InTheWild.io).
EIP tracks 2 public exploits from researchers including Metasploit, Or Peles, wvu, sinn3r, Brent Cook, Jacob Robles, Matthew Kienow, Shelby Pace, Chris Lee, Cale Black, including a Metasploit module exploits/linux/http/axis_srv_parhand_rce.
AI-analyzed exploit summary This Metasploit module exploits an authentication bypass and command injection vulnerability in Axis Network Cameras to achieve remote code execution as root. It leverages the .srv functionality and the parhand service via D-Bus commands.
Description
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
Exploits (2)
This Metasploit module exploits an authentication bypass and command injection vulnerability in Axis Network Cameras to achieve remote code execution as root. It leverages the .srv functionality and the parhand service via D-Bus commands.
This Metasploit module exploits an authentication bypass in Axis Network Camera's .srv functionality and a command injection in parhand to achieve remote code execution as root. It leverages D-Bus communication to inject and execute arbitrary commands.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H