gist.github.com
https://gist.github.com/keniver/86ebef688fb274b534da51ef1a84dd3e CVE-2021-30168
CRITICAL
MERIT LILIN ENT.CO.,LTD. P2/Z2/P3/Z3 IP camera - Sensitive Data Exposure-1
Record summary
CVE-2021-30168 has a selected CVSS score of 9.8 (critical).
Description
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 25, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
P2/Z2/P3/Z3 IP camera firmwareBrowse MERIT LILIN ENT.CO.,LTD. / P2/Z2/P3/Z3 IP camera firmware | CVE List | Through 7.1.94.8908 | affected |
p2r8852e2_firmwareBrowse meritlilin / p2r8852e2_firmware | VulnCheck | Version data not supplied | |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-30168 chtsecurity.com
https://www.chtsecurity.com/news/0b733a38-e616-4ff3-86a6-13e710643388 meritlilin.com
https://www.meritlilin.com/assets/uploads/support/file/M00166-TW.pdf twcert.org.tw
https://www.twcert.org.tw/tw/cp-132-4678-aad70-1.html