CVE-2017-9829: Path Traversal
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9829?
CVE-2017-9829 has been classified with a high severity due to its potential for remote exploitation and filesystem access.
How do I fix CVE-2017-9829?
To fix CVE-2017-9829, update the VIVOTEK network cameras to the latest firmware provided by the manufacturer.
What type of attack does CVE-2017-9829 facilitate?
CVE-2017-9829 facilitates remote file reading attacks via crafted HTTP requests.
Which VIVOTEK camera models are affected by CVE-2017-9829?
Affected models include the VIVOTEK Network Camera IB8369, FD8164, and FD816BA with specific vulnerable firmware versions.
What impact does CVE-2017-9829 have on affected devices?
CVE-2017-9829 allows attackers to read sensitive files from the Linux filesystem of the affected cameras.