PT-2018-11610 · Kerui · Kerui Wifi Endoscope Camera

Utku Sen

·

Published

2018-10-22

·

Updated

2020-08-24

·

CVE-2018-13114

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions KERUI Wifi Endoscope Camera (YPC99) (affected versions not specified)
Description The issue concerns missing authentication and improper input validation, allowing an attacker to execute arbitrary commands with a length limit of 19 characters via the ssid value in the body of a SETSSID command. For example, an attacker could use ssid:;ping 192.168.1.2 to execute a command.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-13114

Affected Products

Kerui Wifi Endoscope Camera