PT-2017-6564 · Airlink101 · Airlink101 Skyipcam1620W

Joaquin Rodriguez Varela

+1

·

Published

2017-07-24

·

Updated

2018-10-09

·

CVE-2015-2280

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera version FW AIC1620W 1.1.0-12 20120709 r1192.pck
Description The issue allows remote authenticated users to execute arbitrary OS commands. This is achieved by injecting shell metacharacters in the mac parameter of the snwrite.cgi endpoint.
Recommendations For AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera version FW AIC1620W 1.1.0-12 20120709 r1192.pck, consider restricting access to the snwrite.cgi endpoint until a patch is available. As a temporary workaround, avoid using the mac parameter in the snwrite.cgi endpoint to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2280

Affected Products

Airlink101 Skyipcam1620W