Impact
The vulnerability lies in the H.View IP camera’s certificate generation interface, which accepts unsanitized XML fields that are directly embedded into a backend OS command. Because the device executes these commands with elevated privileges, a malicious authenticated user can inject arbitrary commands, turning the camera into a target for command execution. This is a classic OS command injection flaw (CWE-78).
Affected Systems
No specific firmware or software version numbers are supplied in the CVE data, so any firmware containing the described certificate creation mechanism is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.6 classifies the flaw as high‑severity. The EPSS score is not available and the flaw is not listed in CISA's KEV catalog, indicating that while exploitation is feasible, there is currently no evidence of active widespread attacks. The vulnerability requires authentication to the camera; therefore, the attack vector is likely local or remote network access to an authenticated user. Once authenticated, an attacker can inject shell commands during certificate creation, escalating privileges on the device.
OpenCVE Enrichment