Vulnerability Description
Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and TVIP51550 MG.1.6.03 cameras allow remote attackers to execute code as root.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Abus | Tvip 10000 Firmware | - |
| Abus | Tvip 10000 | - |
| Abus | Tvip 10001 Firmware | - |
| Abus | Tvip 10001 | - |
| Abus | Tvip 10005 Firmware | - |
| Abus | Tvip 10005 | - |
| Abus | Tvip 10005A Firmware | - |
| Abus | Tvip 10005A | - |
| Abus | Tvip 10005B Firmware | - |
| Abus | Tvip 10005B | - |
| Abus | Tvip 10050 Firmware | - |
| Abus | Tvip 10050 | - |
| Abus | Tvip 10051 Firmware | - |
| Abus | Tvip 10051 | - |
| Abus | Tvip 10055A Firmware | - |
| Abus | Tvip 10055A | - |
| Abus | Tvip 10055B Firmware | - |
| Abus | Tvip 10055B | - |
| Abus | Tvip 10500 Firmware | - |
| Abus | Tvip 10500 | - |
Related Weaknesses (CWE)
References
- https://sec.maride.cc/posts/abus/ExploitThird Party Advisory
- https://www.ccc.de/en/updates/2019/update-nicht-verfugbar-hersteller-nicht-zu-erThird Party Advisory
- https://sec.maride.cc/posts/abus/ExploitThird Party Advisory
- https://www.ccc.de/en/updates/2019/update-nicht-verfugbar-hersteller-nicht-zu-erThird Party Advisory
FAQ
What is CVE-2018-17558?
CVE-2018-17558 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM....
How severe is CVE-2018-17558?
CVE-2018-17558 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-17558?
Check the references section above for vendor advisories and patch information. Affected products include: Abus Tvip 10000 Firmware, Abus Tvip 10000, Abus Tvip 10001 Firmware, Abus Tvip 10001, Abus Tvip 10005 Firmware.