PT-2019-12733 · Vstarcam · Vstarcam 200V+1
Published
2019-05-23
·
Updated
2021-09-13
·
CVE-2019-12288
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VStarcam 100T (C7824WIP) version KR75.8.53.20
VStarcam 200V (C38S) version KR203.18.1.20
Description
An issue allows manipulation of the web service, network, and account files through a web UI firmware update without any authentication. This can be achieved by an attacker through a manipulated web UI firmware update, allowing access to the device.
Recommendations
For VStarcam 100T (C7824WIP) version KR75.8.53.20, consider restricting access to the firmware update feature until a fix is available.
For VStarcam 200V (C38S) version KR203.18.1.20, consider restricting access to the firmware update feature until a fix is available.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vstarcam 100T
Vstarcam 200V