Schneider Electric Pelco...

- AV AC AU C I A
发布: 2017-07-11
修订: 2025-04-13

Pelco IP cameras suffer from a code execution vulnerability. The affected cameras suffer from authenticated remote code execution vulnerability. The POST parameter 'enable_leds' located in the update() function called via the GeneralSetupController.php script is not properly sanitised before being used in writeLedConfig() function to enable led state to on or off. A remote attacker can exploit this issue and execute arbitrary system commands granting her system access with root privileges using a specially crafted request and escape sequence to system shell.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息