CVE-2019-15498
HIGHVera Edge Home Controller <1.7.4452 - Command Injection
Title source: llmDescription
cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/cmh/webcam.sh.
Scores
CVSS v3
8.8
EPSS
0.0117
EPSS Percentile
78.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-88
Status
published
Affected Products (1)
getvera/vera_edge_firmware
Timeline
Published
Aug 23, 2019
Tracked Since
Feb 18, 2026