CVE-2024-13892

Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to command injection. During the initialization process, a user has to use a mobile app to provide devices with Access Point credentials. This input is not properly sanitized, what allows for command injection. The vendor has not replied to reports, so the patching status remains unknown. Newer firmware versions might be vulnerable as well.
CVSS

No CVSS.

Configurations

No configuration.

History

06 Mar 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-06 14:15

Updated : 2025-03-06 14:15


NVD link : CVE-2024-13892

Mitre link : CVE-2024-13892

CVE.ORG link : CVE-2024-13892


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')