Command Injection Vulnerability in Sony IPELA E Series Network Camera G5 Firmware 1.87.00

Command Injection Vulnerability in Sony IPELA E Series Network Camera G5 Firmware 1.87.00

CVE-2018-3937 · MEDIUM Severity

AV:N/AC:L/AU:S/C:P/I:P/A:P

An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability.

Learn more about our Network Penetration Testing.