CVE-2018-17558
PoC —CVSS 3.1
9.8 critical
EPSS
3%p84
Published
()
Modified
Description
Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and TVIP51550 MG.1.6.03 cameras allow remote attackers to execute code as root.
- Vendors
- abus
- Products
- tvip 10000 firmware, tvip 10001 firmware, tvip 10005 firmware, tvip 10005a firmware, tvip 10005b firmware, tvip 10050 firmware, tvip 10051 firmware, tvip 10055a firmware, tvip 10055b firmware, tvip 10500 firmware, tvip 10550 firmware, tvip 11000 firmware
- Weakness
- CWE-798, CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.