CVE-2018-11560

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
23/06/2018
Last modified:
22/06/2021

Description

The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Control-Flow Hijacking via a crafted usr key, as demonstrated by a long remoteIp parameter to cgi-bin/CGIProxy.fcgi on port 34100.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:insteon:2864-222_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:insteon:2864-222:*:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools