CVE-2023-4249 is a critical command injection vulnerability affecting multiple Zavio IP camera models (CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321) running firmware M2.1.6.05. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to execute arbitrary commands remotely with high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog or having public exploit intelligence like Metasploit or ExploitDB, there is significant community discussion and media coverage, including a hands-on guide for triaging the vulnerability, indicating potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
m2.1.6.05CPE matchmatch criteria | cpe:2.3:o:zavio:cf7500_firmware:m2.1.6.05:*:*:*:*:*:*:* | ||
m2.1.6.05CPE matchmatch criteria | cpe:2.3:o:zavio:cf7300_firmware:m2.1.6.05:*:*:*:*:*:*:* | ||
m2.1.6.05CPE matchmatch criteria | cpe:2.3:o:zavio:cf7201_firmware:m2.1.6.05:*:*:*:*:*:*:* | ||
m2.1.6.05CPE matchmatch criteria | cpe:2.3:o:zavio:cf7501_firmware:m2.1.6.05:*:*:*:*:*:*:* | ||
m2.1.6.05CPE matchmatch criteria | cpe:2.3:o:zavio:cb3211_firmware:m2.1.6.05:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.