9.8

CVE-2021-30167

The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MeritlilinP2r8852e2 Firmware Version < 7.1.94.8908
   MeritlilinP2r8852e2 Version-
MeritlilinP2r8852e4 Firmware Version < 7.1.94.8908
   MeritlilinP2r8852e4 Version-
MeritlilinP2r6852e2 Firmware Version < 7.1.94.8908
   MeritlilinP2r6852e2 Version-
MeritlilinP2r6852e4 Firmware Version < 7.1.94.8908
   MeritlilinP2r6852e4 Version-
MeritlilinP2r6552e2 Firmware Version < 7.1.94.8908
   MeritlilinP2r6552e2 Version-
MeritlilinP2r6552e4 Firmware Version < 7.1.94.8908
   MeritlilinP2r6552e4 Version-
MeritlilinP2r6352ae2 Firmware Version < 7.1.94.8908
   MeritlilinP2r6352ae2 Version-
MeritlilinP2r6352ae4 Firmware Version < 7.1.94.8908
   MeritlilinP2r6352ae4 Version-
MeritlilinP2r3052ae2 Firmware Version < 7.1.94.8908
   MeritlilinP2r3052ae2 Version-
MeritlilinP2g1052 Firmware Version < 7.1.94.8908
   MeritlilinP2g1052 Version-
MeritlilinP2r8822e2 Firmware Version < 7.1.94.8908
   MeritlilinP2r8822e2 Version-
MeritlilinP2r8822e4 Firmware Version < 7.1.94.8908
   MeritlilinP2r8822e4 Version-
MeritlilinP2r6822e2 Firmware Version < 7.1.94.8908
   MeritlilinP2r6822e2 Version-
MeritlilinP2r6822e4 Firmware Version < 7.1.94.8908
   MeritlilinP2r6822e4 Version-
MeritlilinP2r6522e2 Firmware Version < 7.1.94.8908
   MeritlilinP2r6522e2 Version-
MeritlilinP2r6522e4 Firmware Version < 7.1.94.8908
   MeritlilinP2r6522e4 Version-
MeritlilinP2r6322ae2 Firmware Version < 7.1.94.8908
   MeritlilinP2r6322ae2 Version-
MeritlilinP2r6322ae4 Firmware Version < 7.1.94.8908
   MeritlilinP2r6322ae4 Version-
MeritlilinP2r3022ae2 Firmware Version < 7.1.94.8908
   MeritlilinP2r3022ae2 Version-
MeritlilinP2g1022 Firmware Version < 7.1.94.8908
   MeritlilinP2g1022 Version-
MeritlilinP2g1022x Firmware Version < 7.1.94.8908
   MeritlilinP2g1022x Version-
MeritlilinZ2r8852ax Firmware Version < 7.1.94.8908
   MeritlilinZ2r8852ax Version-
MeritlilinZ2r8152x-p Firmware Version < 7.1.94.8908
   MeritlilinZ2r8152x-p Version-
MeritlilinZ2r8152x2-p Firmware Version < 7.1.94.8908
   MeritlilinZ2r8152x2-p Version-
MeritlilinZ2r8052ex25 Firmware Version < 7.1.94.8908
   MeritlilinZ2r8052ex25 Version-
MeritlilinZ2r6552x Firmware Version < 7.1.94.8908
   MeritlilinZ2r6552x Version-
MeritlilinZ2r6452ax Firmware Version < 7.1.94.8908
   MeritlilinZ2r6452ax Version-
MeritlilinZ2r6452ax-p Firmware Version < 7.1.94.8908
   MeritlilinZ2r6452ax-p Version-
MeritlilinZ2r8822ax Firmware Version < 7.1.94.8908
   MeritlilinZ2r8822ax Version-
MeritlilinZ2r8122x-p Firmware Version < 7.1.94.8908
   MeritlilinZ2r8122x-p Version-
MeritlilinZ2r8122x2-p Firmware Version < 7.1.94.8908
   MeritlilinZ2r8122x2-p Version-
MeritlilinZ2r8022ex25 Firmware Version < 7.1.94.8908
   MeritlilinZ2r8022ex25 Version-
MeritlilinZ2r6522x Firmware Version < 7.1.94.8908
   MeritlilinZ2r6522x Version-
MeritlilinZ2r6422ax Firmware Version < 7.1.94.8908
   MeritlilinZ2r6422ax Version-
MeritlilinZ2r6422ax-p Firmware Version < 7.1.94.8908
   MeritlilinZ2r6422ax-p Version-
MeritlilinP3r6322e2 Firmware Version < 7.1.94.8908
   MeritlilinP3r6322e2 Version-
MeritlilinP3r6522e2 Firmware Version < 7.1.94.8908
   MeritlilinP3r6522e2 Version-
MeritlilinP3r8822e2 Firmware Version < 7.1.94.8908
   MeritlilinP3r8822e2 Version-
MeritlilinZ3r6422x3 Firmware Version < 7.1.94.8908
   MeritlilinZ3r6422x3 Version-
MeritlilinZ3r6522x Firmware Version < 7.1.94.8908
   MeritlilinZ3r6522x Version-
MeritlilinZ3r8922x3 Firmware Version < 7.1.94.8908
   MeritlilinZ3r8922x3 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.56% 0.872
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
twcert@cert.org.tw 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.