Shell Command Injection Vulnerability in VIVOTEK Network Cameras
CVE-2017-9828
What is CVE-2017-9828?
The web service located at '/cgi-bin/admin/testserver.cgi' in many VIVOTEK Network Cameras is susceptible to shell command injection attacks. This vulnerability allows remote attackers to execute arbitrary shell commands with root privileges by sending specially crafted HTTP requests. The attack is facilitated through the use of shell metacharacters in the 'senderemail' parameter, potentially compromising the integrity and security of the affected devices. This issue has been verified on specific models such as the VIVOTEK IB8369, FD8164, and FD816BA, with similar firmware versions likely being vulnerable.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
58% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability Reserved
Vulnerability published
