CVE-2017-8225
CRITICAL 9.8EPSS 35.4%
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI.
- CVSS v3.0
- 9.8 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 35.36% chance of exploitation in the next 30 days, 98th percentile
- Nuclei
- critical · CWE-200
- Published
- 2017-04-25
- Updated
- 2024-09-17
Proof-of-concept exploits (4)
- http://seclists.org/fulldisclosure/2017/Mar/23
- https://pierrekim.github.io/blog/2017-03-08-camera-goahead-0day.html#pre-auth-info-leak-g…
- K3ysTr0K3R/CVE-2017-8225-EXPLOIT9★ · 2023-09-10
- kienquoc102/CVE-2017-82252★ · 2021-10-30