VYPR

G Cam\/efd 2250 Firmware

by Geutebrück

CVEs (22)

  • CVE-2021-33543CriSep 13, 2021
    risk 0.73cvss 9.8epss 0.81

    Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user authentication settings. This can lead to manipulation of the device and denial of service.

  • CVE-2018-7532CriMar 22, 2018
    risk 0.64cvss 9.8epss 0.08

    Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow remote code execution.

  • CVE-2018-7520CriMar 22, 2018
    risk 0.64cvss 9.8epss 0.02

    An improper access control vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which could allow a full configuration download, including passwords.

  • CVE-2018-7528CriMar 22, 2018
    risk 0.59cvss 9.1epss 0.02

    An SQL injection vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow an attacker to alter stored data.

  • CVE-2021-33544HigSep 13, 2021
    risk 0.57cvss 7.2epss 0.95

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2018-7524HigMar 22, 2018
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow an unauthorized user to be added to the system.

  • CVE-2021-33549HigSep 13, 2021
    risk 0.55cvss 7.2epss 0.66

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2020-16205HigAug 14, 2020
    risk 0.55cvss 7.2epss 0.61

    Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2 and 1.12.14.5).

  • CVE-2021-33554HigSep 13, 2021
    risk 0.54cvss 7.2epss 0.57

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2021-33553HigSep 13, 2021
    risk 0.54cvss 7.2epss 0.49

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2021-33552HigSep 13, 2021
    risk 0.54cvss 7.2epss 0.49

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2021-33551HigSep 13, 2021
    risk 0.54cvss 7.2epss 0.49

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2021-33550HigSep 13, 2021
    risk 0.54cvss 7.2epss 0.57

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2021-33548HigSep 13, 2021
    risk 0.54cvss 7.2epss 0.57

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2018-7516HigMar 22, 2018
    risk 0.48cvss 7.3epss 0.01

    A server-side request forgery vulnerability has been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which could lead to proxied network scans.

  • CVE-2021-33547HigSep 13, 2021
    risk 0.47cvss 7.2epss 0.03

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the profile parameter which may allow an attacker to remotely execute arbitrary code.

  • CVE-2021-33546HigSep 13, 2021
    risk 0.47cvss 7.2epss 0.03

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the name parameter, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2021-33545HigSep 13, 2021
    risk 0.47cvss 7.2epss 0.03

    Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the counter parameter which may allow an attacker to remotely execute arbitrary code.

  • CVE-2019-10958HigJan 17, 2020
    risk 0.47cvss 7.2epss 0.03

    Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to network configuration to supply system commands to the server, leading to remote code execution as root.

  • CVE-2019-10956HigJan 17, 2020
    risk 0.47cvss 7.2epss 0.03

    Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to execute commands as root.

Page 1 of 2