PT-2025-9923 · Smartwares · Smartwares Cameras

Marcin Wyczechowski

+2

·

Publicado

2025-03-06

·

Atualizado

2025-03-09

·

CVE-2024-13892

CVSS v4.0

7.7

Alta

VetorAV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Smartwares cameras versions up to 3.3.0
Description The issue concerns command injection during the initialization process of the cameras. When a user provides Access Point credentials through a mobile app, the input is not properly sanitized, allowing for command injection. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited. The vendor has not replied to reports, so the patching status remains unknown.
Recommendations For versions up to 3.3.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-02433
BDU:2025-02434
BDU:2025-02435
CVE-2024-13892

Produtos afetados

Smartwares Cameras