PT-2024-33028 · Tuya · Kerui Hd 3Mp 1080P Tuya Camera
Published
2024-10-30
·
Updated
2024-11-01
·
CVE-2024-48214
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
KERUI HD 3MP 1080P Tuya Camera version 1.0.4
Description
The issue concerns a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of the parameters, either
SSID or PASSWORD, in the JSON data contained within the QR code. By doing so, the attacker can execute arbitrary code on the camera.Recommendations
For KERUI HD 3MP 1080P Tuya Camera version 1.0.4, consider disabling the QR code connection feature until a patch is available to prevent exploitation of the command injection vulnerability. Restrict access to the camera's network connection to minimize the risk of arbitrary code execution. Avoid using the
SSID or PASSWORD parameters in the QR code's JSON data until the issue is resolved.Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kerui Hd 3Mp 1080P Tuya Camera