CVE-2017-12577
Published on: 08/24/2018 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:26:29 PM UTC
Certain versions of Cs-qr20 from Planex contain the following vulnerability:
An issue was discovered on the PLANEX CS-QR20 1.30. A hardcoded account / password ("admin:password") is used in the Android application that allows attackers to use a hidden API URL "/goform/SystemCommand" to execute any command with root permission.
- CVE-2017-12577 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 10 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Full Disclosure: CVE-2017-12577: an hardcode credential in PLANEX CS-QR20 | Mailing List Third Party Advisory seclists.org text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Planex | Cs-qr20 | - | All | All | All |
Hardware
| Planex | Cs-qr20 | - | All | All | All |
Operating System | Planex | Cs-qr20 Firmware | 1.30 | All | All | All |
Operating System | Planex | Cs-qr20 Firmware | 1.30 | All | All | All |
Application | Planex | Smacam Night Vision | - | All | All | All |
Application | Planex | Smacam Night Vision | - | All | All | All |
- cpe:2.3:h:planex:cs-qr20:-:*:*:*:*:*:*:*:
- cpe:2.3:h:planex:cs-qr20:-:*:*:*:*:*:*:*:
- cpe:2.3:o:planex:cs-qr20_firmware:1.30:*:*:*:*:*:*:*:
- cpe:2.3:o:planex:cs-qr20_firmware:1.30:*:*:*:*:*:*:*:
- cpe:2.3:a:planex:smacam_night_vision:-:*:*:*:*:android:*:*:
- cpe:2.3:a:planex:smacam_night_vision:-:*:*:*:*:android:*:*:
No vendor comments have been submitted for this CVE