CVE-2018-19007
9.8
CRITICAL · CVSS 3.0 · EPSS 3.9% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
In Geutebrueck GmbH E2 Camera Series versions prior to 1.12.0.25 the DDNS configuration (in the Network Configuration panel) is vulnerable to an OS system command injection as root.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.88% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-12-14 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| geutebrueck | g-cam\/efd-2251 |
| geutebrueck | g-cam\/efd-2251 firmware |
| geutebrueck | g-cam\/ewpc-2275 |
| geutebrueck | g-cam\/ewpc-2275 firmware |
References
→ the Explorer · watch your stack · NVD