Vulnerabilities > CVE-2018-7520 - Unspecified vulnerability in Geutebrueck G-Cam/Efd-2250 Firmware and Topfd-2125 Firmware

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
geutebrueck
critical
exploit available

Summary

An improper access control vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which could allow a full configuration download, including passwords.

Exploit-Db

descriptionGeutebruck 5.02024 G-Cam/EFD-2250 - 'simple_loglistjs.cgi' Remote Command Execution (Metasploit). Webapps exploit for Hardware platform
idEDB-ID:44957
last seen2018-07-02
modified2018-07-02
published2018-07-02
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44957/
titleGeutebruck 5.02024 G-Cam/EFD-2250 - 'simple_loglistjs.cgi' Remote Command Execution (Metasploit)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/148380/geutebruck5-exec.rb.txt
idPACKETSTORM:148380
last seen2018-07-03
published2018-07-02
reporterDavy Douhine
sourcehttps://packetstormsecurity.com/files/148380/Geutebruck-simple_loglistjs.cgi-Remote-Command-Execution.html
titleGeutebruck simple_loglistjs.cgi Remote Command Execution