Impact
The firmware for the JAIOTlink C492A‑W6 Wi‑Fi IP camera contains an OS command injection flaw in the NetSDK/Factory SetMAC HTTP endpoint that allows an attacker with valid camera credentials to inject shell commands. By crafting a Wireless parameter string that begins with a valid MAC‑like prefix followed by a semicolon and a malicious payload, the camera bypasses incomplete sscanf() validation and passes the string unsanitized to an echo command executed through a system() wrapper. This results in arbitrary command execution on the device, giving the attacker full control. The weakness is classified as OS command injection (CWE‑78).
Affected Systems
Vendor: JAIOTlink, Product: C492A‑W6 Wi‑Fi IP Camera, Firmware version: 4.8.30.57701411.
Risk and Exploitability
The CVSS score of 8.7 signals a high severity vulnerability. An EPSS score of 2% indicates a measurable likelihood that the weakness will be exploited. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires an authenticated session with valid camera credentials; an attacker can craft a SetMAC request over the network to achieve remote code execution, potentially moving laterally to other devices on the network.
OpenCVE Enrichment