Sony IPELA Network Camera Stack Buffer Overflow Vulnerability Allowing Remote Code Execution

Vulnerability

A stack buffer overflow vulnerability has been identified in the Sony IPELA Network Camera model SNC-DH120, running firmware version 1.82.01. The vulnerability resides in the ftpclient.cgi endpoint, where it allows remote attackers to execute arbitrary code. Exploitation involves sending a crafted POST request with oversized data to the FTP client functionality, which could lead to remote code execution or a denial-of-service condition.

Impact

Exploitation of this vulnerability causes a stack-based buffer overflow, which can be exploited to execute arbitrary code on the affected device. Alternatively, it could lead to a denial-of-service scenario.

Reproduction

The vulnerability can be reproduced by sending a POST request to the ftpclient.cgi endpoint with oversized data. This can be done using a tool like curl, by including a large payload that exceeds the buffer's capacity. The request must be made to a device running the vulnerable firmware version 1.82.01.

Remediation

Users are advised to update to Sony IPELA Network Camera firmware version 1.88.00 or later, available through the Sony Professional Support Resources.

Added: Dec 10, 2025, 9:52 PM
Updated: Dec 10, 2025, 9:52 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
7.7
relevance
1.4
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.