« Volver al listado

CVE-2019-12289

Estado: ModificadaCrítica (9.8)—

Se detectó un problema en upgrade_firmware.cgi en dispositivos VStarcam 100T (C7824WIP) CH-sys-48.53.75.119 ~ 123 y 200V (C38S) CH-sys-48.53.203.119 ~ 123. Un comando remoto puede ser ejecutado por medio de una actualización del firmware del sistema sin autenticación. El atacante puede modificar los archivos dentro del firmware interno o incluso robar información de la cuenta mediante la ejecución de un comando.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-12289",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-05-23T18:29:01.590",
  "references": [
    {
      "url": "http://f1security.co.kr/cve/cve_190314.htm",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://f1security.co.kr/cve/cve_190314.htm",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in upgrade_firmware.cgi on VStarcam 100T (C7824WIP) CH-sys-48.53.75.119~123 and 200V (C38S) CH-sys-48.53.203.119~123 devices. A remote command can be executed through a system firmware update without authentication. The attacker can modify the files within the internal firmware or even steal account information by executing a command."
    },
    {
      "lang": "es",
      "value": "Se detectó un problema en upgrade_firmware.cgi en dispositivos VStarcam 100T (C7824WIP) CH-sys-48.53.75.119 ~ 123 y 200V (C38S) CH-sys-48.53.203.119 ~ 123. Un comando remoto puede ser ejecutado por medio de una actualización del firmware del sistema sin autenticación. El atacante puede modificar los archivos dentro del firmware interno o incluso robar información de la cuenta mediante la ejecución de un comando."
    }
  ],
  "lastModified": "2026-06-17T02:14:22.220",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:vstracam:c7824wip_firmware:ch-sys-48.53.75.119\\~123:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "429E2AE1-E013-43F9-9B5D-EBAAD5920B93"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:vstracam:c7824wip:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "97637208-3AD6-486D-965A-518C92BCD31F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:vstracam:c38s_firmware:ch-sys-48.53.203.119\\~123:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9CF87B55-56D0-4301-8E92-1BA2D088ED80"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:vstracam:c38s:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "60179B92-B799-49E3-92A7-F151C7182F4B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}