VYPR
Unrated severityNVD Advisory· Published Jun 7, 2023· Updated Jan 7, 2025

CVE-2023-30400

CVE-2023-30400

Description

An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network configuration script within the MCU's operating system allows attackers to perform arbitrary command execution via a crafted wifi SSID or password.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Command injection vulnerability in Anyka AK3918EV300 MCU v18 allows arbitrary command execution via crafted wifi SSID or password.

Vulnerability

A command injection vulnerability exists in the network configuration script of the Anyka Microelectronics AK3918EV300 MCU operating system (version 18). An attacker can inject arbitrary commands by providing a specially crafted wifi SSID or password during the configuration process. This affects the firmware running on the MCU, which is used in various hidden camera modules [1][2].

Exploitation

An attacker with network access to the device can trigger the vulnerability by supplying a malicious SSID or password parameter. No authentication is required; the attack can be performed by connecting to the device's network configuration interface or by intercepting and modifying network setup commands. The attacker can then execute arbitrary shell commands on the MCU [2].

Impact

Successful exploitation allows arbitrary command execution on the MCU, leading to complete compromise of the device. The attacker can gain full control over the camera, including access to video streams, file system manipulation, and potential pivot to internal networks. The impact is considered critical due to the ability to execute code with elevated privileges [2].

Mitigation

As of the publication date, no official fix is available from the manufacturer. The vendor acknowledged the issue but has not released a patch or recall affected units. Users are advised to isolate the device on a separate network segment and monitor for suspicious activity. No workaround has been disclosed [1][2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.