vendor:
VT-HDOC16BR_Firmware_1.02Y_UI_1.0.1.R
by:
bashis
8,8
CVSS
HIGH
Remote Code Execution and Information Disclosure
78
CWE
Product Name: VT-HDOC16BR_Firmware_1.02Y_UI_1.0.1.R
Affected Version From: VT-HDOC4E_Firmware_1.21A_UI_1.1.C.6 and VT-HDOC16BR_Firmware_1.02Y_UI_1.0.1.R
Affected Version To: VT-HDOC4E_Firmware_1.21A_UI_1.1.C.6 and VT-HDOC16BR_Firmware_1.02Y_UI_1.0.1.R
Patch Exists: YES
Related CWE: N/A
CPE: h:vitek:vt-hdoc16br_firmware_1.02y_ui_1.0.1.r
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2017
Vitek RCE and Information Disclosure (and possible other OEM)
A remote code execution vulnerability exists in Vitek CCTV cameras due to improper validation of user-supplied input. An attacker can send a specially crafted HTTP request to the vulnerable device to execute arbitrary code on the system. Additionally, an attacker can send a specially crafted HTTP request to the vulnerable device to disclose sensitive information such as firmware version, model name, MAC address, IP address, subnet mask, default gateway, DNS server, system time, system name, system location, admin name, admin password, user name, and user password.
Mitigation:
Upgrade to the latest version of the firmware and apply the latest security patches.