CVE-2018-12258
6.8
Vector
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: NVD
Description
An issue was discovered on Momentum Axel 720P 5.1.8 devices. Custom Firmware Upgrade is possible via an SD Card. With physical access, an attacker can upgrade the firmware in under 60 seconds by inserting an SD card containing the firmware with name 'ezviz.dav' and rebooting.
Affected (1)
Products: Apollotechnologiesinc: Momentum Axel 720p Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.1.8 |
| Running on/with | Platform Versions |
|---|---|
Apollotechnologiesinc Momentum Axel 720p | All versions |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.