Vulnerability Description
An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices. A remote command can be executed through a system firmware update without authentication. The attacker can modify the files within the internal firmware or even steal account information by executing a command.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vstracam | C7824Wip Firmware | ch-sys-48.53.75.119\~123 |
| Vstracam | C7824Wip | - |
| Vstracam | C38S Firmware | ch-sys-48.53.203.119\~123 |
| Vstracam | C38S | - |
Related Weaknesses (CWE)
References
- http://f1security.co.kr/cve/cve_190314.htmBroken Link
- http://f1security.co.kr/cve/cve_190314.htmBroken Link
FAQ
What is CVE-2019-12289?
CVE-2019-12289 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices. A remote command can be executed through a system ...
How severe is CVE-2019-12289?
CVE-2019-12289 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-12289?
Check the references section above for vendor advisories and patch information. Affected products include: Vstracam C7824Wip Firmware, Vstracam C7824Wip, Vstracam C38S Firmware, Vstracam C38S.