CVE-2017-9828: OS Command Injection

Published Jun 23, 2017
·
Updated

'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected. An attack uses shell metacharacters in the senderemail parameter.

Affected Software

6 affected components
Vivotek Network Camera Ib8369 Firmware=ib8369-vvtk-0102a
Vivotek Network Camera IB8369
Vivotek Network Camera Fd8164 Firmware=fd8164-_vvtk-0200b
Vivotek Network Camera Fd8164
Vivotek Network Camera Fd816ba Firmware=fd816ba-vvtk-010101.
Vivotek Network Camera Fd816ba

Event History

Jun 23, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2017-9828?

CVE-2017-9828 is considered a critical vulnerability due to its ability to allow remote attackers to execute arbitrary commands as root.

2

How do I fix CVE-2017-9828?

To mitigate CVE-2017-9828, update the firmware of VIVOTEK network cameras to the latest version that addresses this vulnerability.

3

Which devices are affected by CVE-2017-9828?

CVE-2017-9828 affects multiple VIVOTEK network cameras including the IB8369 and FD8164 models using specific firmware versions.

4

Can CVE-2017-9828 be exploited remotely?

Yes, CVE-2017-9828 can be exploited remotely via a crafted HTTP request without requiring physical access to the device.

5

What types of attacks can result from CVE-2017-9828?

Exploiting CVE-2017-9828 can lead to unauthorized command execution, which can compromise the camera's security and control.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203