CVE-2021-30166

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
28/04/2021
Last modified:
05/05/2021

Description

The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:meritlilin:p2r8852e2_firmware:*:*:*:*:*:*:*:* 7.1.94.8908 (excluding)
cpe:2.3:h:meritlilin:p2r8852e2:-:*:*:*:*:*:*:*
cpe:2.3:o:meritlilin:p2r8852e4_firmware:*:*:*:*:*:*:*:* 7.1.94.8908 (excluding)
cpe:2.3:h:meritlilin:p2r8852e4:-:*:*:*:*:*:*:*
cpe:2.3:o:meritlilin:p2r6852e2_firmware:*:*:*:*:*:*:*:* 7.1.94.8908 (excluding)
cpe:2.3:h:meritlilin:p2r6852e2:-:*:*:*:*:*:*:*
cpe:2.3:o:meritlilin:p2r6852e4_firmware:*:*:*:*:*:*:*:* 7.1.94.8908 (excluding)
cpe:2.3:h:meritlilin:p2r6852e4:-:*:*:*:*:*:*:*
cpe:2.3:o:meritlilin:p2r6552e2_firmware:*:*:*:*:*:*:*:* 7.1.94.8908 (excluding)
cpe:2.3:h:meritlilin:p2r6552e2:-:*:*:*:*:*:*:*
cpe:2.3:o:meritlilin:p2r6552e4_firmware:*:*:*:*:*:*:*:* 7.1.94.8908 (excluding)
cpe:2.3:h:meritlilin:p2r6552e4:-:*:*:*:*:*:*:*
cpe:2.3:o:meritlilin:p2r6352ae2_firmware:*:*:*:*:*:*:*:* 7.1.94.8908 (excluding)
cpe:2.3:h:meritlilin:p2r6352ae2:-:*:*:*:*:*:*:*
cpe:2.3:o:meritlilin:p2r6352ae4_firmware:*:*:*:*:*:*:*:* 7.1.94.8908 (excluding)