CVE Feed

    Dashboard / CVE / CVE-2017-17105

    CVE-2017-17105

    Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a cgi-bin/iptest.cgi?cmd=iptest.cgi&-time="1504225666237"&-url=$(reboot) request.

    Published:Dec 18, 2017
    Last Modified:Apr 20, 2025
    EPS:Dec 18, 2017
    EPSS Score:0.91749
    CVSS Score:9.8

    Affected Products

    Vendor
    Zivif
    Product
    Pr115-204-p-rs
    Vendor
    Zivif
    Product
    Pr115-204-p-rs Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High