Vulnerability Description
KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of the parameters, either SSID or PASSWORD, in the JSON data contained within the QR code. By that, the attacker can execute arbitrary code on the camera.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-48214?
CVE-2024-48214 is a vulnerability with a CVSS score of 8.4 (HIGH). KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, una...
How severe is CVE-2024-48214?
CVE-2024-48214 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-48214?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.