CVE-2020-7879: ipTIME C200 IP Camera command injection vulnerability
This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is transferred to the --header option in wget binary, and there is no validation check. This vulnerability allows remote attackers to execute remote command.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7879?
CVE-2020-7879 is a vulnerability that was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS.
What is the severity of CVE-2020-7879?
The severity of CVE-2020-7879 is critical with a CVSS score of 9.8.
What software is affected by CVE-2020-7879?
The Iptime C200 Firmware up to version 1.0.16 is affected.
How can I fix CVE-2020-7879?
There is no known fix for CVE-2020-7879 at the moment. It is recommended to keep the affected software up to date and follow any security patches or recommendations provided by the vendor.
Where can I find more information about CVE-2020-7879?
You can find more information about CVE-2020-7879 at [insert link to reference].