Vulnerability CVE-2021-30167


Published: 2021-04-28

Description:
The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user??s information and escalate privileges to control the devices.

Type:

CWE-522

(Insufficiently Protected Credentials)

 References:
https://www.meritlilin.com/assets/uploads/support/file/M00166-TW.pdf
https://www.twcert.org.tw/tw/cp-132-4676-391a5-1.html
https://www.chtsecurity.com/news/0b733a38-e616-4ff3-86a6-13e710643388
https://gist.github.com/keniver/86ebef688fb274b534da51ef1a84dd3e

Copyright 2024, cxsecurity.com

 

Back to Top