packetstormsecurity.com
http://packetstormsecurity.com/files/171136/ABUS-Security-Camera-TVIP-20000-21150-LFI-Remote-Code-Execution.html CVE-2023-26609
HIGH
abus tvip_20000-21150_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2023-26609 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
ABUS TVIP 20000-21150 devices allows remote attackers to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
tvip_20000-21150_firmwareBrowse abus / tvip_20000-21150_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
2Catalogued exploits
ExploitDBABUS Security Camera TVIP 20000-21150 - LFI_ RCE and SSH Root AccessExploitDB exploitby d1g@segfault.netNot analyzed1 file
Repository PoCs
GitHubD1G17/CVE-2023-26609Repository PoCby D1G17Stars: 0Not analyzed2 files
References
420230227 [NetworkSEC NWSSA] CVE-2023-26609: ABUS Security Camera LFI, RCE and SSH Rootmailing list
http://seclists.org/fulldisclosure/2023/Feb/16 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-26609 nwsec.de
https://nwsec.de/NWSSA-001-2023.txt