CVE-2024-7616

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
12/08/2024
Last modified:
13/08/2024

Description

A vulnerability was found in Edimax IC-6220DC and IC-5150W up to 3.06. It has been rated as critical. Affected by this issue is the function cgiFormString of the file ipcam_cgi. The manipulation of the argument host leads to command injection. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:edimax:ic-6220dc_firmware:*:*:*:*:*:*:*:* 3.06 (including)
cpe:2.3:h:edimax:ic-6220dc:-:*:*:*:*:*:*:*
cpe:2.3:o:edimax:ic-5150w_firmware:*:*:*:*:*:*:*:* 3.06 (including)
cpe:2.3:h:edimax:ic-5150w:-:*:*:*:*:*:*:*