CVE-2020-23826: OS Command Injection
DISPUTED The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10176 .
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-23826?
CVE-2020-23826 is a vulnerability in the Yale WIPC-303W camera that allows for remote command execution through command injection via the HTTP API.
What is the severity of CVE-2020-23826?
CVE-2020-23826 has a severity rating of 8.8 (high).
What is the affected software for CVE-2020-23826?
The affected software is the Assaabloy Yale Wipc-303w firmware versions 2.21 through 2.31.
How can the vulnerability CVE-2020-23826 be exploited?
The vulnerability CVE-2020-23826 can be exploited through command injection via the HTTP API of the Yale WIPC-303W camera.
Are there any references for CVE-2020-23826?
Yes, references for CVE-2020-23826 can be found at the following links: [Link 1](https://firedome.io/blog/firedome-discloses-0-day-vulnerabilities-in-yale-ip-cameras/), [Link 2](https://lp.firedome.io/hubfs/Yale%20WIPC-301W%20RCE%20Vulnerability%20Report%205-6.pdf), [Link 3](https://whiterosezex.blogspot.com/2021/01/cve-2020-23826-rce-vulnerability-in.html).