#VU16536 OS command injection in Geutebrück E2 Series IP Cameras - CVE-2018-19007
Published: December 13, 2018 / Updated: December 14, 2018
Geutebrück E2 Series IP Cameras
GEUTEBRÜCK GmbH
Description
The vulnerability allows a remote high-privileged attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to OS system command injection in the DDNS configuration (in the Network Configuration panel). A remote attacker can supply a specially crafted input to inject and execute arbitrary shell commands with root privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.