Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and TVIP51550 MG.1.6.03 cameras allow remote attackers to execute code as root.

Project Subscriptions

Vendors Products
Tvip 10000 Subscribe
Tvip 10000 Firmware Subscribe
Tvip 10001 Subscribe
Tvip 10001 Firmware Subscribe
Tvip 10005 Subscribe
Tvip 10005 Firmware Subscribe
Tvip 10005a Subscribe
Tvip 10005a Firmware Subscribe
Tvip 10005b Subscribe
Tvip 10005b Firmware Subscribe
Tvip 10050 Subscribe
Tvip 10050 Firmware Subscribe
Tvip 10051 Subscribe
Tvip 10051 Firmware Subscribe
Tvip 10055a Subscribe
Tvip 10055a Firmware Subscribe
Tvip 10055b Subscribe
Tvip 10055b Firmware Subscribe
Tvip 10500 Subscribe
Tvip 10500 Firmware Subscribe
Tvip 10550 Subscribe
Tvip 10550 Firmware Subscribe
Tvip 11000 Subscribe
Tvip 11000 Firmware Subscribe
Tvip 11050 Subscribe
Tvip 11050 Firmware Subscribe
Tvip 11500 Subscribe
Tvip 11500 Firmware Subscribe
Tvip 11501 Subscribe
Tvip 11501 Firmware Subscribe
Tvip 11502 Subscribe
Tvip 11502 Firmware Subscribe
Tvip 11550 Subscribe
Tvip 11550 Firmware Subscribe
Tvip 11551 Subscribe
Tvip 11551 Firmware Subscribe
Tvip 11552 Subscribe
Tvip 11552 Firmware Subscribe
Tvip 20000 Subscribe
Tvip 20000 Firmware Subscribe
Tvip 20050 Subscribe
Tvip 20050 Firmware Subscribe
Tvip 20500 Subscribe
Tvip 20500 Firmware Subscribe
Tvip 20550 Subscribe
Tvip 20550 Firmware Subscribe
Tvip 21000 Subscribe
Tvip 21000 Firmware Subscribe
Tvip 21050 Subscribe
Tvip 21050 Firmware Subscribe
Tvip 21500 Subscribe
Tvip 21500 Firmware Subscribe
Tvip 21501 Subscribe
Tvip 21501 Firmware Subscribe
Tvip 21502 Subscribe
Tvip 21502 Firmware Subscribe
Tvip 21550 Subscribe
Tvip 21550 Firmware Subscribe
Tvip 21551 Subscribe
Tvip 21551 Firmware Subscribe
Tvip 21552 Subscribe
Tvip 21552 Firmware Subscribe
Tvip 22500 Subscribe
Tvip 22500 Firmware Subscribe
Tvip 31000 Subscribe
Tvip 31000 Firmware Subscribe
Tvip 31001 Subscribe
Tvip 31001 Firmware Subscribe
Tvip 31050 Subscribe
Tvip 31050 Firmware Subscribe
Tvip 31500 Subscribe
Tvip 31500 Firmware Subscribe
Tvip 31501 Subscribe
Tvip 31501 Firmware Subscribe
Tvip 31550 Subscribe
Tvip 31550 Firmware Subscribe
Tvip 31551 Subscribe
Tvip 31551 Firmware Subscribe
Tvip 32500 Subscribe
Tvip 32500 Firmware Subscribe
Tvip 51500 Subscribe
Tvip 51500 Firmware Subscribe
Tvip 51550 Subscribe
Tvip 51550 Firmware Subscribe
Tvip 71500 Subscribe
Tvip 71500 Firmware Subscribe
Tvip 71501 Subscribe
Tvip 71501 Firmware Subscribe
Tvip 71550 Subscribe
Tvip 71550 Firmware Subscribe
Tvip 71551 Subscribe
Tvip 71551 Firmware Subscribe
Tvip 72500 Subscribe
Tvip 72500 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2018-9311 Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and TVIP51550 MG.1.6.03 cameras allow remote attackers to execute code as root.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 11 Sep 2024 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-78

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-11T19:29:40.804Z

Reserved: 2018-09-26T00:00:00

Link: CVE-2018-17558

cve-icon Vulnrichment

Updated: 2024-08-05T10:54:09.266Z

cve-icon NVD

Status : Modified

Published: 2023-10-26T22:15:08.383

Modified: 2024-11-21T03:54:35.827

Link: CVE-2018-17558

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses