Impact
The vulnerability lies in the GenericFastJsonRedisSerializer used by the API Endpoint of wvp-GB28181-pro. It deserializes JSON data without proper validation, which can allow an attacker to supply malicious objects. Based on the description that the flaw can be exploited remotely and that an exploit has been released, this flaw is likely capable of enabling arbitrary code execution on the host system.
Affected Systems
The affected product is 648540858 wvp-GB28181-pro, versions up to and including 2.7.4. The specific component impacted is the RedisTemplateConfig.java file in the API Endpoint module. No other vendors, products, or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity issue. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, as the flaw can be triggered by sending crafted data to the API Endpoint over the network. Publicly available exploit code suggests that attackers can leverage the flaw without user interaction.
OpenCVE Enrichment