CVE-2020-7848: Input Validation
Published Feb 17, 2021
·Updated
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary OS commands via cookie value.
Affected Software
2 affected components
IPTIME C200 Firmware=1.0.12
IPTIME C200
Event History
Feb 17, 2021
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-7848.
2
What is the severity level of CVE-2020-7848?
CVE-2020-7848 has a severity level of high.
3
What is the affected software for CVE-2020-7848?
The affected software for CVE-2020-7848 is the EFM ipTIME C200 IP Camera with firmware version 1.0.12.
4
How can an attacker exploit CVE-2020-7848?
An attacker can exploit CVE-2020-7848 by sending a GET request that executes arbitrary OS commands via the cookie value in the /login.cgi?logout=1 script.
5
Is the ipTIME C200 affected by CVE-2020-7848?
No, the ipTIME C200 is not affected by CVE-2020-7848.