Search Results (23 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-7879 1 Iptime 2 C200, C200 Firmware 2024-11-21 8.8 High
This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is transferred to the --header option in wget binary, and there is no validation check. This vulnerability allows remote attackers to execute remote command.
CVE-2020-7848 1 Iptime 2 C200, C200 Firmware 2024-11-21 8 High
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary OS commands via cookie value.
CVE-2020-7847 1 Iptime 18 Nas-i, Nas-i Firmware, Nas-ii and 15 more 2024-11-21 7.4 High
The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affects: pTIME NAS 1.4.36.