CVE Published: 07/09/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: jpcert |
Vendor: I-O DATA DEVICE, INC. |
Product: Multiple I-O DATA network camera products Status : PUBLISHED
CVE-2018-0661 Description
Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) allow an attacker on the same network segment to bypass access restriction to add files on a specific directory that may result in executing arbitrary OS commands/code or information including credentials leakage or alteration.