PT-2018-11610 · Kerui · Kerui Wifi Endoscope Camera
Utku Sen
·
Published
2018-10-22
·
Updated
2020-08-24
·
CVE-2018-13114
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
KERUI Wifi Endoscope Camera (YPC99) (affected versions not specified)
Description
The issue concerns missing authentication and improper input validation, allowing an attacker to execute arbitrary commands with a length limit of 19 characters via the
ssid value in the body of a SETSSID command. For example, an attacker could use ssid:;ping 192.168.1.2 to execute a command.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kerui Wifi Endoscope Camera