VYPR

IP camera device

by Merit LILIN

CVEs (2)

  • CVE-2026-0855HigJan 12, 2026
    risk 0.57cvss 8.8epss 0.01

    Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.

  • CVE-2021-30166HigApr 28, 2021
    risk 0.47cvss 7.2epss 0.04

    The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.