PT-2025-26991 · Beward · Beward N100 Ip Camera

Gjoko Krstic

·

Published

2025-06-26

·

Updated

2025-11-20

·

CVE-2025-34042

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Beward N100 IP Camera version M2.1.6.04C014
Description An authenticated command injection issue exists in the Beward N100 IP Camera firmware. An attacker with web interface access can inject arbitrary system commands through the ServerName and TimeZone parameters in the servetest CGI page. These parameters are unsafely incorporated into backend system calls without sufficient input validation. Successful exploitation can lead to remote code execution with root privileges. The Shadowserver Foundation observed exploitation evidence on 2024-12-02 UTC. The vulnerable component is the servetest CGI page, specifically the handling of the ServerName and TimeZone parameters.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the servetest CGI page to minimize the risk of exploitation.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-34042

Affected Products

Beward N100 Ip Camera