PT-2025-9923 · Smartwares · Smartwares Cameras

Marcin Wyczechowski

+2

·

Published

2025-03-06

·

Updated

2025-03-09

·

CVE-2024-13892

CVSS v4.0

7.7

High

VectorAV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Smartwares cameras versions up to 3.3.0
Description The issue concerns command injection during the initialization process of the cameras. When a user provides Access Point credentials through a mobile app, the input is not properly sanitized, allowing for command injection. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited. The vendor has not replied to reports, so the patching status remains unknown.
Recommendations For versions up to 3.3.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02433
BDU:2025-02434
BDU:2025-02435
CVE-2024-13892

Affected Products

Smartwares Cameras