CVE-2017-8225

On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:wificam:wireless_ip_camera_\(p2p\)_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:wificam:wireless_ip_camera_\(p2p\):-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-04-25 20:59

Updated : 2023-12-10 12:01


NVD link : CVE-2017-8225

Mitre link : CVE-2017-8225

CVE.ORG link : CVE-2017-8225


JSON object : View

Products Affected

wificam

  • wireless_ip_camera_\(p2p\)
  • wireless_ip_camera_\(p2p\)_firmware
CWE
CWE-522

Insufficiently Protected Credentials