Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-12288

Опубликовано: 23 мая 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network, and account files can be manipulated through a web UI firmware update without any authentication. The attacker can achieve access to the device through a manipulated web UI firmware update.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:vstarcam:c7824iwp_firmware:kr75.8.53.20:*:*:*:*:*:*:*
cpe:2.3:h:vstarcam:c7824iwp:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:vstracm:c38s_firmware:kr203.18.1.20:*:*:*:*:*:*:*
cpe:2.3:h:vstracm:c38s:-:*:*:*:*:*:*:*

EPSS

Процентиль: 56%
0.00336
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-306

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network, and account files can be manipulated through a web UI firmware update without any authentication. The attacker can achieve access to the device through a manipulated web UI firmware update.

EPSS

Процентиль: 56%
0.00336
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-306