CVE-2017-9828: OS Command Injection
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected. An attack uses shell metacharacters in the senderemail parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9828?
CVE-2017-9828 is considered a critical vulnerability due to its ability to allow remote attackers to execute arbitrary commands as root.
How do I fix CVE-2017-9828?
To mitigate CVE-2017-9828, update the firmware of VIVOTEK network cameras to the latest version that addresses this vulnerability.
Which devices are affected by CVE-2017-9828?
CVE-2017-9828 affects multiple VIVOTEK network cameras including the IB8369 and FD8164 models using specific firmware versions.
Can CVE-2017-9828 be exploited remotely?
Yes, CVE-2017-9828 can be exploited remotely via a crafted HTTP request without requiring physical access to the device.
What types of attacks can result from CVE-2017-9828?
Exploiting CVE-2017-9828 can lead to unauthorized command execution, which can compromise the camera's security and control.