PT-2017-6564 · Airlink101 · Airlink101 Skyipcam1620W
Joaquin Rodriguez Varela
+1
·
Published
2017-07-24
·
Updated
2018-10-09
·
CVE-2015-2280
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera version FW AIC1620W 1.1.0-12 20120709 r1192.pck
Description
The issue allows remote authenticated users to execute arbitrary OS commands. This is achieved by injecting shell metacharacters in the
mac parameter of the snwrite.cgi endpoint.Recommendations
For AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera version FW AIC1620W 1.1.0-12 20120709 r1192.pck, consider restricting access to the snwrite.cgi endpoint until a patch is available. As a temporary workaround, avoid using the
mac parameter in the snwrite.cgi endpoint to minimize the risk of exploitation.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Airlink101 Skyipcam1620W