CVE-2021-3577
binatoneglobal halo\+_camera_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2021-3577 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 22, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Binatone Hubble CamerasBrowse Motorola / Binatone Hubble Cameras | CVE List | various | affected |
halo\+_camera_firmwareBrowse binatoneglobal / halo\+_camera_firmware | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHMotorola Baby Monitors - Remote Command ExecutionCVSS 8.8
Motorola Baby Monitors contains multiple interface vulnerabilities could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected device, potentially leading to unauthorized access, data theft, or further compromise of the network.
Remediation
Apply the latest firmware update provided by Motorola to mitigate the vulnerability and ensure the device is not accessible from untrusted networks.
Source: ProjectDiscovery