Impact
The vulnerability allows an authenticated attacker to write arbitrary shell scripts to a writable area of persistent storage on the device, then trigger their execution through the "/Anyka/config" HTTP endpoint by employing the popen() system call. This flaw, categorized as an interpreter engine execution fault (CWE‑94), results in the device executing the attacker‑supplied code, granting full control over the camera’s operating system. Once staged, the malicious script runs with the device’s privileges and persists across reboots, enabling a long‑term compromise.
Affected Systems
JAIOTlink C492A‑W6 Wi‑Fi IP cameras running firmware version 4.8.30.57701411 are the only known affected hosts. No other vendors or firmware revisions have been identified as impacted.
Risk and Exploitability
The reported CVSS score of 7.7 indicates a high‑severity issue. The EPSS score of less than 1% implies a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, so no widespread active exploitation has been documented. Attackers must first gain authenticated access to the camera—typically via local network presence or credential theft—before they can write the script and invoke the vulnerable endpoint. Once executed, the attacker obtains persistent remote control that survives device reboots.
OpenCVE Enrichment