Cross-Site Scripting Vulnerability in VIVOTEK Network Cameras
CVE-2018-18005

6.1MEDIUM

Key Information:

Vendor

Vivotek

Status
Vendor
CVE Published:
3 January 2019

What is CVE-2018-18005?

VIVOTEK Network Camera Series products with firmware versions 0x06x to 0x08x are susceptible to a Cross-Site Scripting (XSS) vulnerability. This security flaw allows remote attackers to inject and execute arbitrary JavaScript through a specially crafted URL query string. Such exploitation could lead to unauthorized actions, data theft, or manipulation of the camera's user interface, posing risks to user privacy and security. It is crucial for users to update their firmware to mitigate this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.