ZeroHour

CVE-2021-30166

CVSS 3.1
7.2 high
EPSS
4%p89
Published
()
Modified
Description

The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.

Vendors
meritlilin
Products
p2r8852e2 firmware, p2r8852e4 firmware, p2r6852e2 firmware, p2r6852e4 firmware, p2r6552e2 firmware, p2r6552e4 firmware, p2r6352ae2 firmware, p2r6352ae4 firmware, p2r3052ae2 firmware, p2g1052 firmware, p2r8822e2 firmware, p2r8822e4 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.