Command Injection Vulnerability in GoAhead Web Server Affects Foscam and Vstarcam IP Cameras
CVE-2017-5675
8.8HIGH
What is CVE-2017-5675?
A command injection vulnerability has been identified in the GoAhead web server utilized by several IP camera models, including those from Foscam and Vstarcam. This vulnerability arises from the mail-sending form within the mail.htm page, where an attacker can exploit the receiver1 field to inject malicious commands. These commands are executed with root privileges, potentially allowing unauthorized access and control over the device. It is crucial for users of affected devices to implement security measures and firmware updates to mitigate the risks associated with this vulnerability.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved