CVE-2021-26614: IpTime C200 IP camera remote code execution vulnerability
iusget.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the arbitrary shell command.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2021-26614.
What is the title of this vulnerability?
The title of this vulnerability is 'ius_get.cgi in IpTime C200 camera allows remote code execution.'
What is the severity of CVE-2021-26614?
The severity of CVE-2021-26614 is critical with a CVSS score of 9.8.
Which software is affected by CVE-2021-26614?
The IpTime C200 camera firmware up to version 1.060 is affected by CVE-2021-26614.
Is the ipTIME C200 vulnerable to CVE-2021-26614?
No, the ipTIME C200 is not vulnerable to CVE-2021-26614.
How can a remote attacker exploit CVE-2021-26614?
A remote attacker can exploit CVE-2021-26614 by sending crafted parameters to the exposed vulnerable web service interface which invokes arbitrary shell commands.
Are there any fixes available for CVE-2021-26614?
Please refer to the vendor's website or security advisory for available fixes for CVE-2021-26614.