peter bassill · operator
$ cve CVE-2013-3539 JSON

CVE-2013-3539 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 8.8% (pctl 95)

Patch early

A public exploit exists.

Description

Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS8.76% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2013-10-01
Last modified2026-06-16

Affected (11)

VendorProduct
ovislinkairlive wl2600cam
sonysnc ch140
sonysnc ch180
sonysnc ch240
sonysnc ch280
sonysnc dh140
sonysnc dh140t
sonysnc dh180
sonysnc dh240
sonysnc dh240t
sonysnc dh280

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD