Vulnerability Details CVE-2017-8225
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.756
EPSS Ranking 98.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2017-8225
-
cpe:2.3:h:wificam:wireless_ip_camera_(p2p):-
-
cpe:2.3:o:wificam:wireless_ip_camera_(p2p)_firmware:-