CVE-2018-5725
UnknownEPSS 4.72%
Last modified
CVE-2018-5725 is a vulnerability of currently unknown severity. MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server.. EPSS estimates a 4.72% chance of exploitation in the next 30 days.
Description
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Barni | Master Ip Camera01 Firmware | 3.3.4.2103 |
References
- http://syrion.me/blog/master-ipcam/Exploit, Third Party Advisory
- https://packetstormsecurity.com/files/145935/Master-IP-CAM-01-Hardcoded-Password-Unauthenticated-Access.htmlThird Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/43693/Third Party Advisory, VDB Entry
- http://syrion.me/blog/master-ipcam/Exploit, Third Party Advisory
- https://packetstormsecurity.com/files/145935/Master-IP-CAM-01-Hardcoded-Password-Unauthenticated-Access.htmlThird Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/43693/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5725?
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server.
How severe is CVE-2018-5725?
Severity scoring for CVE-2018-5725 is pending analysis. The EPSS model estimates a 4.72% probability of exploitation in the next 30 days.
How do I fix CVE-2018-5725?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5717Memory write mechanism in NCR S2 Dispenser controller before…
- CVE-2018-5718Improper restriction of write operations within the bounds o…
- CVE-2018-5720An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wi…
- CVE-2018-5721Stack-based buffer overflow in the ej_update_variables funct…8.8
- CVE-2018-5723MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded passwo…
- CVE-2018-5724MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated C…
- CVE-2018-5726MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers …
- CVE-2018-5727In OpenJPEG 2.3.0, there is an integer overflow vulnerabilit…
- CVE-2018-5728Cobham Sea Tel 121 build 222701 devices allow remote attacke…
- CVE-2018-5729MIT krb5 1.6 or later allows an authenticated kadmin with pe…4.7
- CVE-2018-5730MIT krb5 1.6 or later allows an authenticated kadmin with pe…3.8
- CVE-2018-5731An issue was discovered in Heimdal PRO 2.2.190. As part of t…
Are you affected by CVE-2018-5725?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
