CVE-2021-47709
HIGHCOMMAX Smart Home Ruvie CCTV Bridge DVR Service - Unauthenticated Denial of Service via setconf Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47709. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated configuration write vulnerability in COMMAX Smart Home Ruvie CCTV Bridge DVR Service, allowing an attacker to modify DVR settings and trigger a denial-of-service (DoS) via a crafted POST request to the /goform/setconf endpoint.
Description
COMMAX Smart Home System allows an unauthenticated attacker to change configuration and cause denial-of-service through the setconf endpoint. Attackers can trigger a denial-of-service scenario by sending a malformed request to the setconf endpoint.
Exploits (1)
This exploit demonstrates an unauthenticated configuration write vulnerability in COMMAX Smart Home Ruvie CCTV Bridge DVR Service, allowing an attacker to modify DVR settings and trigger a denial-of-service (DoS) via a crafted POST request to the /goform/setconf endpoint.
References (4)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N