CVE-2015-2279 is a critical OS command injection vulnerability affecting AirLive BU-2015, BU-3026, and MD-3025 IP cameras. An unauthenticated remote attacker can execute arbitrary operating system commands by injecting shell metacharacters into specific parameters within the cgi_test.cgi script. This vulnerability carries a CVSS v3 score of 9.8 (Critical), indicating a severe risk with no user interaction required and complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, exploit code is publicly available via ExploitDB, and it has received community discussion and media coverage, suggesting awareness among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.03.18CPE matchmatch criteria | cpe:2.3:o:airlive:bu-2015_firmware:1.03.18:*:*:*:*:*:*:* | ||
1.43CPE matchmatch criteria | cpe:2.3:o:airlive:bu-3026_firmware:1.43:*:*:*:*:*:*:* | ||
1.81CPE matchmatch criteria | cpe:2.3:o:airlive:md-3025_firmware:1.81:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.