PT-2019-14226 · Vera · Vera Edge Home Controller
Published
2019-08-23
·
Updated
2020-08-24
·
CVE-2019-15498
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Vera Edge Home Controller version 1.7.4452
Description
The issue allows remote unauthenticated users to execute arbitrary OS commands. This is achieved through argument injection in the
username parameter to the "/cgi-bin/cmh/webcam.sh" API endpoint.Recommendations
For Vera Edge Home Controller version 1.7.4452, avoid using the
username parameter in the "/cgi-bin/cmh/webcam.sh" API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the "/cgi-bin/cmh/webcam.sh" endpoint to minimize the risk of exploitation.Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vera Edge Home Controller