CVE-2017-9828 is a critical shell command injection vulnerability affecting the web service of various VIVOTEK Network Cameras, including models like IB8369, FD8164, and FD816BA. An unauthenticated remote attacker can execute arbitrary shell commands as root by injecting metacharacters into the 'senderemail' parameter of a crafted HTTP request to the '/cgi-bin/admin/testserver.cgi' endpoint. With a CVSS score of 9.8 (CRITICAL), this vulnerability requires no user interaction or prior authentication, allowing for complete compromise of confidentiality, integrity, and availability. While there is no confirmed active exploitation or public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
ib8369-vvtk-0102aCPE matchmatch criteria | cpe:2.3:o:vivotek:network_camera_ib8369_firmware:ib8369-vvtk-0102a:*:*:*:*:*:*:* | ||
fd8164-_vvtk-0200bCPE matchmatch criteria | cpe:2.3:o:vivotek:network_camera_fd8164_firmware:fd8164-_vvtk-0200b:*:*:*:*:*:*:* | ||
fd816ba-vvtk-010101.CPE matchmatch criteria | cpe:2.3:o:vivotek:network_camera_fd816ba_firmware:fd816ba-vvtk-010101.:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.