UDP Technology/Geutebrück camera devices: Command injection in date parameter leading to RCE
70Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 7.2epss 57%
from disclosure to weapon0 days
Published on NVDSep 13
metasploitJul 8
VulnCheck+756d
exploitation probability
57%top 1% of all CVEs
observed exploitation
yesVulnCheck
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H