Executive brief
JAIOTlink Wi-Fi IP cameras contain a security flaw that allows an authorized user to take full control of the device. By sending a specially crafted command to the camera's management interface, an attacker can execute arbitrary code, potentially leading to unauthorized surveillance, data theft, or use of the device in further network attacks. This impact is significant as it compromises the privacy and operational integrity of the camera system.
Technical details
An OS command injection vulnerability exists in the JAIOTlink C492A-W6 Wi-Fi IP camera firmware version 4.8.30.57701411. The flaw is located in the HTTP PUT NetSDK/Factory SetMAC endpoint, specifically within the handling of the 'Wireless' parameter. While the application attempts to validate the input using sscanf(), it only performs partial validation. An attacker can bypass this by providing a valid MAC-like prefix followed by a semicolon and a shell payload. This unsanitized input is subsequently passed to an 'echo' command executed via a system() wrapper, allowing for remote code execution with the privileges of the web service. Authentication is required to reach the vulnerable endpoint.
Affected products
- JAIOTlink C492A-W6 Wi-Fi IP Camera 4.8.30.57701411
Timeline
- 2026-07-01: advisory: NVD and VulnCheck published the advisory.
References
- https://github.com/rwprimitives/jaiotlink-c492a-wifi-camera/blob/main/writeups/01-setmac-command-injection.md
- https://www.amazon.com/stores/JAIOTlink/page/3B00DC41-70C3-4BAA-925C-3D222C2633D5?lp_asin=B0GX1BNZ78&ref_=ast_bln&store_ref=bl_ast_dp_brandlogo_sto
- https://www.vulncheck.com/advisories/jaiotlink-c492a-w6-os-command-injection-via-setmac-endpoint