CVE-2008-5674 describes critical array index errors in the HTTP server of Darkwet Network webcamXP versions 3.72.440.0 and earlier, and beta 4.05.280 and earlier. These vulnerabilities are triggered by invalid parameters to the 'pocketpc' and 'show_gallery_pic' components. With a CVSS score of 9.4, this flaw allows unauthenticated remote attackers to cause a denial of service (device crash) and read arbitrary portions of memory, presenting a complete impact on confidentiality and availability. Although not listed on CISA's KEV catalog, public exploit code is available on ExploitDB, and the CVE has a higher-than-average EPSS score and community discussion, indicating active interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.72.440.0CPE matchmatch criteria | cpe:2.3:a:darkwet:webcam_xp:*:*:*:*:*:*:*:* | ||
1.02.432CPE matchmatch criteria | cpe:2.3:a:darkwet:webcam_xp:1.02.432:*:*:*:*:*:*:* | ||
1.02.535CPE matchmatch criteria | cpe:2.3:a:darkwet:webcam_xp:1.02.535:*:*:*:*:*:*:* | ||
1.6.945CPE matchmatch criteria | cpe:2.3:a:darkwet:webcam_xp:1.6.945:*:*:*:*:*:*:* | ||
2.20CPE matchmatch criteria | cpe:2.3:a:darkwet:webcam_xp:2.20:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.