header-logo
Suggest Exploit
vendor:
IP Camera
by:
icekam,xiao13,Rainbow,tfsec
8,1
CVSS
HIGH
Denial-of-Service (DoS)
20
CWE
Product Name: IP Camera
Affected Version From: Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, TN540
Affected Version To: Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, TN540
Patch Exists: YES
Related CWE: CVE-2021-40378
CPE: h:compro_technology:ip_camera
Metasploit: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2021

Compro Technology IP Camera – ‘killps.cgi’ Denial-of-Service (DoS)

There is a backdoor prefabricated in the device in this path. Accessing the file through the browser after logging in will cause the device to delete all data (including the data of the camera itself). Payload:Visit this page after logging in /cgi-bin/support/killps.cgi

Mitigation:

Restrict access to the killps.cgi page and ensure that only authorized users can access it.
Source

Exploit-DB raw data:

# Exploit Title: Compro Technology IP Camera - 'killps.cgi' Denial-of-Service (DoS)
# Date: 2021-09-30
# Exploit Author: icekam,xiao13,Rainbow,tfsec
# Software Link: http://www.comprotech.com.hk/
# Version: Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, TN540
# CVE : CVE-2021-40378

There is a backdoor prefabricated in the device in this path. Accessing the
file through the browser after logging in will cause the device to delete
all data (including the data of the camera itself).

Payload:Visit this page after logging in
/cgi-bin/support/killps.cgi

please refer to:
https://github.com/icekam/0day/blob/main/Compro-Technology-Camera-has-multiple-vulnerabilities.md