High severity7.2NVD Advisory· Published Apr 28, 2021· Updated Jun 17, 2026
CVE-2021-30166
CVE-2021-30166
Description
The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- MERIT LILIN ENT.CO.,LTD./P2/Z2/P3/Z3 IP camera firmwarev5Range: unspecified
Patches
Vulnerability mechanics
References
4- gist.github.com/keniver/86ebef688fb274b534da51ef1a84dd3envdThird Party Advisory
- www.chtsecurity.com/news/0b733a38-e616-4ff3-86a6-13e710643388nvdThird Party Advisory
- www.meritlilin.com/assets/uploads/support/file/M00166-TW.pdfnvdVendor Advisory
- www.twcert.org.tw/tw/cp-132-4676-391a5-1.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.