ID

VAR-202104-1274


CVE

CVE-2021-30167


TITLE

network camera device Access control error vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202104-2067

DESCRIPTION

The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices

Trust: 0.99

sources: NVD: CVE-2021-30167 // VULMON: CVE-2021-30167

IOT TAXONOMY

category:['camera device']sub_category:camera

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:meritlilinmodel:z3r8922x3scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r6452ax-pscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r6552e2scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r8822e2scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r8852e4scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r8822e4scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r8052ex25scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r6852e2scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r6822e2scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p3r6522e2scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r6552e4scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r6822e4scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r8852axscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r6422axscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r6852e4scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2g1022scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r6522xscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r6522e4scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r6522e2scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r6352ae4scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r8122x2-pscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2g1052scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r6352ae2scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r8152x-pscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r6322ae2scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r8122x-pscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z3r6522xscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r3052ae2scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r6422ax-pscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r6452axscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2g1022xscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r6552xscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p3r6322e2scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p3r8822e2scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r6322ae4scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z3r6422x3scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r8152x2-pscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r8822axscope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:z2r8022ex25scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r8852e2scope:ltversion:7.1.94.8908

Trust: 1.0

vendor:meritlilinmodel:p2r3022ae2scope:ltversion:7.1.94.8908

Trust: 1.0

sources: NVD: CVE-2021-30167

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-30167
value: HIGH

Trust: 1.0

twcert@cert.org.tw: CVE-2021-30167
value: CRITICAL

Trust: 1.0

CNNVD: CNNVD-202104-2067
value: CRITICAL

Trust: 0.6

VULMON: CVE-2021-30167
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2021-30167
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

twcert@cert.org.tw: CVE-2021-30167
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: VULMON: CVE-2021-30167 // CNNVD: CNNVD-202104-2067 // NVD: CVE-2021-30167 // NVD: CVE-2021-30167

PROBLEMTYPE DATA

problemtype:CWE-522

Trust: 1.0

problemtype:CWE-306

Trust: 1.0

sources: NVD: CVE-2021-30167

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202104-2067

TYPE

access control error

Trust: 0.6

sources: CNNVD: CNNVD-202104-2067

PATCH

title:network camera device Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=148774

Trust: 0.6

sources: CNNVD: CNNVD-202104-2067

EXTERNAL IDS

db:NVDid:CVE-2021-30167

Trust: 1.8

db:CNNVDid:CNNVD-202104-2067

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:VULMONid:CVE-2021-30167

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2021-30167 // CNNVD: CNNVD-202104-2067 // NVD: CVE-2021-30167

REFERENCES

url:https://www.meritlilin.com/assets/uploads/support/file/m00166-tw.pdf

Trust: 1.7

url:https://www.twcert.org.tw/tw/cp-132-4676-391a5-1.html

Trust: 1.7

url:https://www.chtsecurity.com/news/0b733a38-e616-4ff3-86a6-13e710643388

Trust: 1.7

url:https://gist.github.com/keniver/86ebef688fb274b534da51ef1a84dd3e

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2021-30167

Trust: 0.6

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/522.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: OTHER: None // VULMON: CVE-2021-30167 // CNNVD: CNNVD-202104-2067 // NVD: CVE-2021-30167

SOURCES

db:OTHERid: -
db:VULMONid:CVE-2021-30167
db:CNNVDid:CNNVD-202104-2067
db:NVDid:CVE-2021-30167

LAST UPDATE DATE

2025-01-30T20:11:57.093000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2021-30167date:2021-05-07T00:00:00
db:CNNVDid:CNNVD-202104-2067date:2022-10-26T00:00:00
db:NVDid:CVE-2021-30167date:2024-11-21T06:03:26.473

SOURCES RELEASE DATE

db:VULMONid:CVE-2021-30167date:2021-04-28T00:00:00
db:CNNVDid:CNNVD-202104-2067date:2021-04-28T00:00:00
db:NVDid:CVE-2021-30167date:2021-04-28T10:15:08.697