peter bassill · operator
$ cve CVE-2018-17879 JSON

CVE-2018-17879

9.8
CRITICAL · CVSS 3.1 · EPSS 21.9% (pctl 98)

Patch early

EPSS 21.9% — above the 10% action threshold.

Description

An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several injection points in various scripts.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS21.85% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2023-10-26
Last modified2026-06-17

Affected (40)

VendorProduct
abustvip 10000
abustvip 10000 firmware
abustvip 10001
abustvip 10001 firmware
abustvip 10005
abustvip 10005 firmware
abustvip 10005a
abustvip 10005a firmware
abustvip 10005b
abustvip 10005b firmware
abustvip 10050
abustvip 10050 firmware
abustvip 10051
abustvip 10051 firmware
abustvip 10055a
abustvip 10055a firmware
abustvip 10055b
abustvip 10055b firmware
abustvip 10500
abustvip 10500 firmware
abustvip 10550
abustvip 10550 firmware
abustvip 11000
abustvip 11000 firmware
abustvip 11050
abustvip 11050 firmware
abustvip 11500
abustvip 11500 firmware
abustvip 11501
abustvip 11501 firmware
abustvip 11502
abustvip 11502 firmware
abustvip 11550
abustvip 11550 firmware
abustvip 11551
abustvip 11551 firmware
abustvip 11552
abustvip 11552 firmware
abustvip 20000
abustvip 20000 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD