TP-Link TL-SC3171 IP Cameras CVE-2013-2578 Multiple Remote Command Injection Vulnerabilities
BID:61529
Info
TP-Link TL-SC3171 IP Cameras CVE-2013-2578 Multiple Remote Command Injection Vulnerabilities
| Bugtraq ID: | 61529 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2578 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2013 12:00AM |
| Updated: | Oct 22 2013 06:46AM |
| Credit: | Flavio de Cristofaro, Andres Blanco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
TP-Link TL-SC3171 IP Cameras CVE-2013-2578 Multiple Remote Command Injection Vulnerabilities
TP-Link TL-SC3171 IP Cameras are prone to multiple remote command-injection vulnerabilities.
Attackers may exploit these issues to execute arbitrary commands with root privileges in the context of the affected device.
TP-Link TL-SC3171 running firmware version LM.1.6.18P12_sign5 is vulnerable; other versions may also be affected.
TP-Link TL-SC3171 IP Cameras are prone to multiple remote command-injection vulnerabilities.
Attackers may exploit these issues to execute arbitrary commands with root privileges in the context of the affected device.
TP-Link TL-SC3171 running firmware version LM.1.6.18P12_sign5 is vulnerable; other versions may also be affected.
Exploit / POC
TP-Link TL-SC3171 IP Cameras CVE-2013-2578 Multiple Remote Command Injection Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept is available:
Solution / Fix
References
TP-Link TL-SC3171 IP Cameras CVE-2013-2578 Multiple Remote Command Injection Vulnerabilities
References:
References: