Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Beward N100 IP Camera Command Injection Vulnerability Leading to Remote Code Execution

Vulnerability

A command injection vulnerability allowing remote code execution has been identified in the Beward N100 IP Camera, specifically in the firmware version M2.1.6.04C014. This vulnerability arises from improper input validation in the servetest CGI page, where the ServerName and TimeZone parameters can be exploited to inject arbitrary system commands. The injected commands are executed with root privileges, compromising the device's security.

Impact

Exploitation of this vulnerability allows authenticated users to execute arbitrary commands on the camera's operating system with root privileges, potentially leading to unauthorized access or control over the device and its functions.

Reproduction

To reproduce this vulnerability, send a GET request to the 'servetest' CGI page with the 'ServerName' or 'TimeZone' parameters. Include the 'Authorization' header with basic authentication credentials. The injected command can be verified by the response, which will include the output of the executed command.

Added: Jun 26, 2025, 5:42 PM
Updated: Jun 26, 2025, 5:42 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.9
remediation
0.0
relevance
0.2
threat
8.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.