漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Puwell IP Camera 2.x - 4.x Unauthenticated Command Injection via DebugShell
Vulnerability Description
Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
隐藏功能
Vulnerability Title
Puwell IP Camera 处理逻辑错误漏洞
Vulnerability Description
Puwell IP Camera是中国Puwell公司的一系列网络摄像机。 Puwell IP Camera 2.x版本至4.x版本存在处理逻辑错误漏洞,该漏洞源于缺乏身份验证和输入清理,可能导致未经身份验证的攻击者通过TCP端口34567向DebugShell接口发送特制JSON有效载荷,进而执行任意操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A