RULE(RULE ID:331997)

Rule General Information
Release Date: 2020-08-28
Rule Name: AirLink101 SkyIPCam1620W OS Command Injection Vulnerability (CVE-2015-2280)
Severity:
CVE ID:
Rule Protection Details
Description: snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the mac parameter.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Network Device
Reference: SecurityFocusBID:75597
ExploitDB:37527
http://packetstormsecurity.com/files/132609/AirLink101-SkyIPCam1620W-OS-Command-Injection.html
http://seclists.org/fulldisclosure/2015/Jul/40
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.airlink101.com/