PT-2017-18227 · Wificam · Wireless Ip Camera (P2P) Wificam

Pierre Kim

+1

·

Published

2017-04-25

·

Updated

2019-10-03

·

CVE-2017-8225

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Wireless IP Camera (P2P) WIFICAM devices (affected versions not specified)
Description The issue concerns incorrect access control to .ini files, which contain credentials. An attacker can bypass authentication by manipulating the loginuse and loginpas parameters in the URI, allowing unauthorized access by providing empty values for these parameters.
Recommendations For Wireless IP Camera (P2P) WIFICAM devices, as a temporary workaround, consider restricting access to the .ini files until a proper fix is available. Avoid using empty values for the loginuse and loginpas parameters in the URI to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8225

Affected Products

Wireless Ip Camera (P2P) Wificam