Command Injection Vulnerability in GoAhead Web Server Affects Foscam and Vstarcam IP Cameras
CVE-2017-5675
8.8HIGH
What is CVE-2017-5675?
A command injection vulnerability has been identified in the GoAhead web server utilized by several IP camera models, including those from Foscam and Vstarcam. This vulnerability arises from the mail-sending form within the mail.htm page, where an attacker can exploit the receiver1 field to inject malicious commands. These commands are executed with root privileges, potentially allowing unauthorized access and control over the device. It is crucial for users of affected devices to implement security measures and firmware updates to mitigate the risks associated with this vulnerability.