peter bassill · operator
$ cve CVE-2019-14699 JSON

CVE-2019-14699

9.8
CRITICAL · CVSS 3.0 · EPSS 6% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filename parameter for remote code execution as root. This occurs in the Mainproc executable file, which can be run from the HTTPD web server.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.99% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2019-08-06
Last modified2026-06-17

Affected (6)

VendorProduct
microdigitalmdc-n2190v
microdigitalmdc-n2190v firmware
microdigitalmdc-n4090
microdigitalmdc-n4090 firmware
microdigitalmdc-n4090w
microdigitalmdc-n4090w firmware

References

→ the Explorer  ·  watch your stack  ·  NVD