vendor:
MOBOTIX Video Security Cameras
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: MOBOTIX Video Security Cameras
Affected Version From: D22M-Secure, T2r1.1.AA, 520 MHz, 128 MByte RAM, MX-V3.5.2.23.r3
Affected Version To: M15D-Secure, T3r4.4, 806 MHz, MX-V4.3.4.50
Patch Exists: YES
Related CWE: N/A
CPE: h:mobotix:d22m-secure
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux 2.6.37.6+, thttpd/2.19-MX
2016
MOBOTIX Video Security Cameras CSRF Add Admin Exploit
The application interface of MOBOTIX Video Security Cameras allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Mitigation:
Validate all input and ensure that requests are only accepted from trusted sources.