CVE-2017-8225 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 35.4% (pctl 98)
Patch early
A public exploit exists.
Description
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 35.36% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-522 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-04-25 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| wificam | wireless ip camera \(p2p\) |
| wificam | wireless ip camera \(p2p\) firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Wireless IP Camera (P2P) WIFICAM - Remote Code Execution | 2017-03-08 |
References
→ the Explorer · watch your stack · NVD