CVE-2019-12288

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
23/05/2019
Last modified:
13/09/2021

Description

An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network, and account files can be manipulated through a web UI firmware update without any authentication. The attacker can achieve access to the device through a manipulated web UI firmware update.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:vstarcam:c7824iwp_firmware:kr75.8.53.20:*:*:*:*:*:*:*
cpe:2.3:h:vstarcam:c7824iwp:-:*:*:*:*:*:*:*
cpe:2.3:o:vstracm:c38s_firmware:kr203.18.1.20:*:*:*:*:*:*:*
cpe:2.3:h:vstracm:c38s:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools