Vulnerability Description
Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a length limit of 19 characters) via the "ssid" value, as demonstrated by ssid:;ping 192.168.1.2 in the body of a SETSSID command.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Keruigroup | Ypc99 Firmware | All versions |
| Keruigroup | Ypc99 | - |
Related Weaknesses (CWE)
References
- https://utkusen.com/blog/multiple-vulnerabilities-on-kerui-endoscope-camera.htmlExploitThird Party Advisory
- https://utkusen.com/blog/multiple-vulnerabilities-on-kerui-endoscope-camera.htmlExploitThird Party Advisory
FAQ
What is CVE-2018-13114?
CVE-2018-13114 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a length limit of 19 characters) via the "ssid" value,...
How severe is CVE-2018-13114?
CVE-2018-13114 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-13114?
Check the references section above for vendor advisories and patch information. Affected products include: Keruigroup Ypc99 Firmware, Keruigroup Ypc99.