PT-2017-2639 · Vivotek · Vivotek Network Camera Fd816Ba+2

Published

2017-06-23

·

Updated

2019-10-03

·

CVE-2017-9828

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VIVOTEK Network Camera IB8369, FD8164, and FD816BA (affected versions not specified)
Description The issue is related to insufficient input processing in the /cgi-bin/admin/testserver.cgi web service of the network camera's firmware. This allows a remote attacker to execute any shell command with superuser privileges by sending a specially crafted HTTP request that uses shell metacharacters in the senderemail parameter.
Recommendations For VIVOTEK Network Camera IB8369, FD8164, and FD816BA, consider disabling the /cgi-bin/admin/testserver.cgi endpoint until a patch is available to prevent exploitation. Restrict access to the senderemail parameter in the affected API endpoint to minimize the risk of shell command injection. Avoid using the senderemail parameter in the /cgi-bin/admin/testserver.cgi endpoint until the issue is resolved.

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01866
CVE-2017-9828

Affected Products

Vivotek Network Camera Fd8164
Vivotek Network Camera Fd816Ba
Vivotek Network Camera Ib8369