CVE-2015-2280
high · 8.8snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the mac parameter.
8.8
CVSS
17.0%
EPSS (exploit prob.)
97th
EPSS percentile
2017-07-25
Published
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| airlink101 | skyipcam1620w_wireless_n_mpeg4_3gpp_firmware | 1.1.0-12_20120709 |
| airlink101 | skyipcam1620w_wireless_n_mpeg4_3gpp | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/132609/AirLink101-SkyIPCam1620W-OS-Command-Injection.html
- http://seclists.org/fulldisclosure/2015/Jul/40
- http://www.securityfocus.com/archive/1/535963/100/0/threaded
- http://www.securityfocus.com/bid/75597
- https://www.coresecurity.com/advisories/airlink101-skyipcam1620w-os-command-injection
- https://www.exploit-db.com/exploits/37527/
- http://packetstormsecurity.com/files/132609/AirLink101-SkyIPCam1620W-OS-Command-Injection.html
- http://seclists.org/fulldisclosure/2015/Jul/40
- http://www.securityfocus.com/archive/1/535963/100/0/threaded
- http://www.securityfocus.com/bid/75597
- https://www.coresecurity.com/advisories/airlink101-skyipcam1620w-os-command-injection
- https://www.exploit-db.com/exploits/37527/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-2280