CVE-2017-10723 describes a memory corruption vulnerability in the Shekar Endoscope firmware (uvc_stream binary) that allows remote code execution. An attacker connected to the device's Wi-Fi SSID can exploit a memcpy overflow in the setwifiname function by sending a crafted UDP request to change the Wi-Fi name. This vulnerability is rated 8.8 HIGH (CVSSv3), indicating a network-based attack with low complexity, requiring low privileges, and leading to high impacts on confidentiality, integrity, and availability. While the vulnerability is severe and could allow access to sensitive video feeds or network footholds, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:ishekar:endoscope_camera_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.