CVE-2020-19642

An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitrary code via editing the 'recdata.db' file to call a specially crafted GoAhead ASP-file on the SD card.
References
Link Resource
https://xn--sb-lka.org/cve/INSMA.txt Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:insma:wifi_mini_spy_1080p_hd_security_ip_camera_firmware:1.9.7b:*:*:*:*:*:*:*
cpe:2.3:h:insma:wifi_mini_spy_1080p_hd_security_ip_camera:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-03-30 03:15

Updated : 2024-02-28 18:28


NVD link : CVE-2020-19642

Mitre link : CVE-2020-19642

CVE.ORG link : CVE-2020-19642


JSON object : View

Products Affected

insma

  • wifi_mini_spy_1080p_hd_security_ip_camera_firmware
  • wifi_mini_spy_1080p_hd_security_ip_camera
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type