← All CVEs

CVE-2017-8225

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI.

9.8
CVSS
35.4%
EPSS (exploit prob.)
98th
EPSS percentile
2017-04-25
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-522

Affected products

VendorProductAffected versions
wificamwireless_ip_camera_(p2p)_firmwareall versions
wificamwireless_ip_camera_(p2p)all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-8225