This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is transferred to the --header option in wget binary, and there is no validation check. This vulnerability allows remote attackers to execute remote command.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: krcert
Published: 2021-11-30T18:37:29
Updated: 2024-08-04T09:41:01.886Z
Reserved: 2020-01-22T00:00:00
Link: CVE-2020-7879
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-11-30T19:15:08.030
Modified: 2024-11-21T05:37:58.000
Link: CVE-2020-7879
Redhat
No data.