CVE ID | |
CVSS SCORE | 10.0, AV:N/AC:L/Au:N/C:C/I:C/A:C |
AFFECTED VENDORS |
Belkin |
AFFECTED PRODUCTS |
NetCam |
VULNERABILITY DETAILS |
The specific flaw exists within the processing of requests to the Wemo SetSmartDevURL API. A crafted request can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code under the context of root. |
ADDITIONAL DETAILS |
07/11/17 - ZDI reported vulnerability to vendor -- Mitigation: |
DISCLOSURE TIMELINE |
|
CREDIT | Dove Chiu Kenney Lu and Tim Yeh of Trend Micro |