CVE-2023-33443

CRITICAL

BES-6024PB-I50H1 VideoPlayTool <2.0.1.0 - Command Injection

Title source: llm

Description

Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrary administrative commands via a crafted payload sent to the desired endpoints.

Exploits (1)

gitlab WORKING POC 1 stars
by FallFur · poc
https://gitlab.com/FallFur/exploiting-unprotected-admin-funcionalities-on-besder-ip-cameras

Scores

CVSS v3 9.8
EPSS 0.0010
EPSS Percentile 26.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-346
Status published

Affected Products (1)

besder/videoplaytool

Timeline

Published Jun 08, 2023
Tracked Since Feb 18, 2026