CVE-2019-12289
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices. A remote command can be executed through a system firmware update without authentication. The attacker can modify the files within the internal firmware or even steal account information by executing a command.
Affected (2)
Products: Vstracam: C7824wip Firmware, C38s Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version ch-sys-48.53.75.119~123 |
| Running on/with | Platform Versions |
|---|---|
Vstracam C7824wip | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version ch-sys-48.53.203.119~123 |
| Running on/with | Platform Versions |
|---|---|
Vstracam C38s | All versions |
References (2)
Timeline
No history available yet.