#VU66940 OS Command Injection in SmaCam CS-QR10 and SmaCam Night Vision CS-QR20 - CVE-2022-38399
Published: September 2, 2022
SmaCam CS-QR10
SmaCam Night Vision CS-QR20
PLANEX COMMUNICATIONS
Description
The vulnerability allows a local attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to missing protection mechanism for alternate hardware interface. An attacker with physical access can connect to the product's certain serial connection and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.