VulnerabilityModified
CVE-2020-23826
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API.
HIGH 8.8EPSS 12.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10176
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 12.65% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- assaabloy/yale wipc-303w firmware
- Source
- cve@mitre.org
References
- https://firedome.io/blog/firedome-discloses-0-day-vulnerabilities-in-yale-ip-cameras/Third Party Advisory
- https://lp.firedome.io/hubfs/Yale%20WIPC-301W%20RCE%20Vulnerability%20Report%205-6.pdfExploit, Third Party Advisory
- https://whiterosezex.blogspot.com/2021/01/cve-2020-23826-rce-vulnerability-in.htmlThird Party Advisory
- https://firedome.io/blog/firedome-discloses-0-day-vulnerabilities-in-yale-ip-cameras/Third Party Advisory
- https://lp.firedome.io/hubfs/Yale%20WIPC-301W%20RCE%20Vulnerability%20Report%205-6.pdfExploit, Third Party Advisory
- https://whiterosezex.blogspot.com/2021/01/cve-2020-23826-rce-vulnerability-in.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.