CVE-2013-1599
CVE-2013-1599
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.00, DCS-7410 1.00, DCS-7510 1.00, and WCS-1100 1.02, which could let a remote malicious user execute arbitrary commands through the camera’s web interface.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/cve/CVE-2013-1599unverifiedcve_referencewww.exploit-db.com/exploits/25138unverifiedexploitdbwww.exploit-db.com/exploits/25138unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://exchange.xforce.ibmcloud.com/vulnerabilities/83941https://packetstormsecurity.com/files/cve/CVE-2013-1599https://seclists.org/fulldisclosure/2013/Apr/253https://www.coresecurity.com/advisories/d-link-ip-cameras-multiple-vulnerabilitieshttp://www.exploit-db.com/exploits/25138http://www.securityfocus.com/bid/59564