Vulnerability Description
The D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has multiple command injection vulnerabilities in the web service framework. An attacker can forge malicious HTTP requests to execute commands; authentication is required before executing the attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Eyeon Baby Monitor Firmware | 1.08.1 |
| Dlink | Eyeon Baby Monitor | - |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2018/Aug/19Mailing ListThird Party Advisory
- https://documents.trendmicro.com/assets/tech_brief_Device_Vulnerabilities_in_theTechnical DescriptionThird Party Advisory
- http://seclists.org/fulldisclosure/2018/Aug/19Mailing ListThird Party Advisory
- https://documents.trendmicro.com/assets/tech_brief_Device_Vulnerabilities_in_theTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2017-11564?
CVE-2017-11564 is a vulnerability with a CVSS score of 8.8 (HIGH). The D-Link EyeOn Baby Monitor (DCS-825L) 1.08.1 has multiple command injection vulnerabilities in the web service framework. An attacker can forge malicious HTTP requests to execute commands; authenti...
How severe is CVE-2017-11564?
CVE-2017-11564 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11564?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Eyeon Baby Monitor Firmware, Dlink Eyeon Baby Monitor.