CVE-2012-4876 describes a critical stack-based buffer overflow vulnerability in the UltraMJCam ActiveX Control used by TRENDnet SecurView TV-IP121WN Wireless Internet Cameras. This flaw allows unauthenticated remote attackers to execute arbitrary code with maximum privileges by providing a specially crafted long string to the OpenFileDlg method. With a CVSS score of 10.0, this vulnerability is easily exploitable over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While not currently listed on CISA's KEV catalog, public exploit code, including a Metasploit module, is readily available, indicating a high potential for exploitation despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.52.18CPE matchmatch criteria | cpe:2.3:a:trendnet:securview_wireless_internet_camera_activex_control:1.1.52.18:*:*:*:*:*:*:* | ||
tv-ip121wnCPE matchmatch criteria | cpe:2.3:h:trendnet:securview_wireless_internet_camera:tv-ip121wn:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.