VulnerabilityModified
CVE-2018-13115
Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the camera stream.
MEDIUM 6.5EPSS 1.02%
Does this matter?
Lower severity and a low EPSS score (1.02%). Track it; it rarely justifies an emergency change on its own.
Description
Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the camera stream. The RTSP server on port 7070 accepts the command STOP to stop streaming, and the command SETSSID to disconnect a user.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 1.02% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- keruigroup/ypc99 firmware
- Source
- cve@mitre.org
References
- https://utkusen.com/blog/multiple-vulnerabilities-on-kerui-endoscope-camera.htmlExploit, Third Party Advisory
- https://utkusen.com/blog/multiple-vulnerabilities-on-kerui-endoscope-camera.htmlExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.