PT-2019-12733 · Vstarcam · Vstarcam 200V+1

Published

2019-05-23

·

Updated

2021-09-13

·

CVE-2019-12288

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VStarcam 100T (C7824WIP) version KR75.8.53.20 VStarcam 200V (C38S) version KR203.18.1.20
Description An issue allows manipulation of the web service, network, and account files through a web UI firmware update without any authentication. This can be achieved by an attacker through a manipulated web UI firmware update, allowing access to the device.
Recommendations For VStarcam 100T (C7824WIP) version KR75.8.53.20, consider restricting access to the firmware update feature until a fix is available. For VStarcam 200V (C38S) version KR203.18.1.20, consider restricting access to the firmware update feature until a fix is available.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12288

Affected Products

Vstarcam 100T
Vstarcam 200V