ZeroHour

CVE-2021-30167

CVSS 3.1
9.8 critical
EPSS
2%p83
Published
()
Modified
Description

The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices.

Vendors
meritlilin
Products
p2r8852e2 firmware, p2r8852e4 firmware, p2r6852e2 firmware, p2r6852e4 firmware, p2r6552e2 firmware, p2r6552e4 firmware, p2r6352ae2 firmware, p2r6352ae4 firmware, p2r3052ae2 firmware, p2g1052 firmware, p2r8822e2 firmware, p2r8822e4 firmware
Weakness
CWE-522, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.