CVE-2020-23826
Description
Command injection in Yale WIPC-303W cameras (firmware 2.21–2.31) allows authenticated remote code execution via the HTTP API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Command injection in Yale WIPC-303W cameras (firmware 2.21–2.31) allows authenticated remote code execution via the HTTP API.
Vulnerability
The Yale WIPC-303W IP camera, running firmware versions 2.21 through 2.31, contains a command injection vulnerability in the HTTP API. The web management interface fails to properly validate user input in a specific API endpoint, allowing an authenticated attacker to inject arbitrary operating system commands. The affected versions are WIPC-303W 2.21 to 2.31 [1].
Exploitation
An attacker must first successfully authenticate to the camera's web-based management interface. With valid credentials, the attacker can send a specially crafted HTTP request to the vulnerable API endpoint, injecting shell metacharacters to execute arbitrary commands on the underlying operating system. No additional user interaction or network position beyond LAN/WAN access to the camera's web server is required [1].
Impact
Successful exploitation results in remote command execution (RCE) at the privilege level of the web server process, enabling the attacker to fully compromise the camera. This could allow information disclosure (e.g., video feed access), configuration changes, or use of the device as a foothold in the local network [1].
Mitigation
As of the reference publication date, no firmware update or official advisory from Yale is available. Users should restrict network access to the camera's web interface, use strong passwords, and monitor vendor support pages for a patch. The camera may be end-of-life; consider replacement if no update is issued [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Yale/WIPC-303W cameradescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- firedome.io/blog/firedome-discloses-0-day-vulnerabilities-in-yale-ip-cameras/mitrex_refsource_MISC
- lp.firedome.io/hubfs/Yale%20WIPC-301W%20RCE%20Vulnerability%20Report%205-6.pdfmitrex_refsource_MISC
- whiterosezex.blogspot.com/2021/01/cve-2020-23826-rce-vulnerability-in.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.