CVE-2017-10724 is a memory corruption vulnerability affecting the Shekar Endoscope camera firmware. An attacker connected to the device's Wi-Fi SSID can exploit a flaw in the UDP daemon's handling of Wi-Fi name change requests, leading to remote code execution. This vulnerability has a CVSS score of 8.8 (High), indicating a critical risk. It is easily exploitable over the network with low privileges and no user interaction, potentially allowing attackers to gain full control of the device, access video feeds, and establish a foothold in air-gapped networks. Currently, there is no evidence of active exploitation, nor are there public Metasploit modules, Nuclei templates, or ExploitDB entries. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:ishekar:endoscope_camera_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.