vendor:
BEWARD N100 H.264 VGA IP Camera
by:
Gjoko 'LiquidWorm' Krstic
5.5
CVSS
MEDIUM
CSRF (Cross-Site Request Forgery)
352
CWE
Product Name: BEWARD N100 H.264 VGA IP Camera
Affected Version From: M2.1.6.04C014
Affected Version To: M2.1.6.04C014
Patch Exists: NO
Related CWE:
CPE: beward-n100_h.264_vga_ip_camera_firmware:m2.1.6.04c014
Platforms Tested: Boa/0.94.14rc21, Farady ARM Linux 2.6
2019
BEWARD N100 H.264 VGA IP Camera M2.1.6 CSRF Add Admin Exploit
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious website.
Mitigation:
Implement CSRF protection mechanisms such as tokens or referer checks in the application.