CVE-2019-12288
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
23/05/2019
Last modified:
13/09/2021
Description
An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devices. The web service, network, and account files can be manipulated through a web UI firmware update without any authentication. The attacker can achieve access to the device through a manipulated web UI firmware update.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:vstarcam:c7824iwp_firmware:kr75.8.53.20:*:*:*:*:*:*:* | ||
| cpe:2.3:h:vstarcam:c7824iwp:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:vstracm:c38s_firmware:kr203.18.1.20:*:*:*:*:*:*:* | ||
| cpe:2.3:h:vstracm:c38s:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



