PT-2017-2639 · Vivotek · Vivotek Network Camera Fd816Ba+2
Published
2017-06-23
·
Updated
2019-10-03
·
CVE-2017-9828
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VIVOTEK Network Camera IB8369, FD8164, and FD816BA (affected versions not specified)
Description
The issue is related to insufficient input processing in the
/cgi-bin/admin/testserver.cgi web service of the network camera's firmware. This allows a remote attacker to execute any shell command with superuser privileges by sending a specially crafted HTTP request that uses shell metacharacters in the senderemail parameter.Recommendations
For VIVOTEK Network Camera IB8369, FD8164, and FD816BA, consider disabling the
/cgi-bin/admin/testserver.cgi endpoint until a patch is available to prevent exploitation.
Restrict access to the senderemail parameter in the affected API endpoint to minimize the risk of shell command injection.
Avoid using the senderemail parameter in the /cgi-bin/admin/testserver.cgi endpoint until the issue is resolved.Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vivotek Network Camera Fd8164
Vivotek Network Camera Fd816Ba
Vivotek Network Camera Ib8369