Record summary

CVE-2020-24217 has a selected CVSS score of 9.8 (critical); EIP currently links 2 catalogued exploits.

Description

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to achieve arbitrary code execution.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 6, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
2

Affected products and versions

1
ProductSourceVersion rangeStatus

iptv\/h.264_video_encoder_firmware

Browse szuray / iptv\/h.264_video_encoder_firmware
VulnCheckVersion data not supplied

Proofs of concept

2

Catalogued exploits

ExploitDBHiSilicon Video Encoders - RCE via unauthenticated command injectionExploitDB exploitby Alexei KojenovNot analyzed1 file
ExploitDB

PoC details
ExploitDBHiSilicon video encoders - RCE via unauthenticated upload of malicious firmwareExploitDB exploitby Alexei KojenovNot analyzed1 file
ExploitDB

PoC details

References

5