Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request.
References
Link | Resource |
---|---|
https://gist.github.com/secgrant/820faeeaa0cb4889edaa1d6fef83deab | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-07-19 13:15
Updated : 2022-07-26 10:32
NVD link : CVE-2022-34538
Mitre link : CVE-2022-34538
JSON object : View
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Products Affected
dw
- megapix
- megapix_firmware