VulnerabilityModified
CVE-2021-30167
The manage users profile services of the network camera device allows an authenticated.
CRITICAL 9.8EPSS 2.44%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.44% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522, CWE-306
- Affected
- meritlilin/p2r8852e2 firmware · meritlilin/p2r8852e4 firmware · meritlilin/p2r6852e2 firmware · meritlilin/p2r6852e4 firmware · meritlilin/p2r6552e2 firmware · meritlilin/p2r6552e4 firmware · meritlilin/p2r6352ae2 firmware · meritlilin/p2r6352ae4 firmware · meritlilin/p2r3052ae2 firmware · meritlilin/p2g1052 firmware · meritlilin/p2r8822e2 firmware · meritlilin/p2r8822e4 firmware · meritlilin/p2r6822e2 firmware · meritlilin/p2r6822e4 firmware · meritlilin/p2r6522e2 firmware · meritlilin/p2r6522e4 firmware · meritlilin/p2r6322ae2 firmware · meritlilin/p2r6322ae4 firmware · meritlilin/p2r3022ae2 firmware · meritlilin/p2g1022 firmware · +21 more
- Source
- twcert@cert.org.tw
References
- https://gist.github.com/keniver/86ebef688fb274b534da51ef1a84dd3eThird Party Advisory
- https://www.chtsecurity.com/news/0b733a38-e616-4ff3-86a6-13e710643388Third Party Advisory
- https://www.meritlilin.com/assets/uploads/support/file/M00166-TW.pdfVendor Advisory
- https://www.twcert.org.tw/tw/cp-132-4676-391a5-1.htmlNot Applicable
- https://gist.github.com/keniver/86ebef688fb274b534da51ef1a84dd3eThird Party Advisory
- https://www.chtsecurity.com/news/0b733a38-e616-4ff3-86a6-13e710643388Third Party Advisory
- https://www.meritlilin.com/assets/uploads/support/file/M00166-TW.pdfVendor Advisory
- https://www.twcert.org.tw/tw/cp-132-4676-391a5-1.htmlNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.