Vulnerability record · CVE-2013-2568 · published 29 January 2020
CVE-2013-2568: Zavio IP Cameras command injection in wireless_mft.cgi ap parameter
Zavio · F3105 Firmware
Zavio IP Cameras through firmware 1.6.3 pass the ap parameter of /cgi-bin/mft/wireless_mft.cgi to a shell without sanitization, allowing OS command injection. The flaw is remotely reachable and unauthenticated per the CVSS vector, so any exposed camera can be turned into an execution point on the local network.
Description
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution with CVSS 9.8 and high EPSS on internet-exposed IoT devices makes this an urgent fix despite the absence of KEV listing.
What it is
Zavio IP Cameras through firmware 1.6.3 pass the ap parameter of /cgi-bin/mft/wireless_mft.cgi to a shell without sanitization, allowing OS command injection. The flaw is remotely reachable and unauthenticated per the CVSS vector, so any exposed camera can be turned into an execution point on the local network.
Impact
An attacker can execute arbitrary commands on the camera with the privileges of the CGI process, gaining full control of the device and a foothold for lateral movement into the camera's network segment.
Attack surface
Reached over the network via an HTTP request to /cgi-bin/mft/wireless_mft.cgi with a crafted ap parameter; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is 0.485 (98.8th percentile) and a Core Security advisory is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Zavio camera firmware beyond 1.6.3 if a fixed release is available; the record does not name a patched version, so confirm with the vendor.
- If no fix exists, isolate cameras on a dedicated VLAN with no route to management or user networks.
- Block or restrict external and cross-segment access to /cgi-bin/mft/wireless_mft.cgi and the camera web interface.
- Disable or replace end-of-life Zavio F3105/F312A units that cannot be patched.
- Change default credentials and disable unused services such as UPnP and remote access.
Detection
- Monitor HTTP request logs and IDS/IPS for requests to /cgi-bin/mft/wireless_mft.cgi with shell metacharacters in the ap parameter.
- Alert on unexpected outbound connections or new processes spawned by the camera's CGI/web service.
- Baseline camera traffic and flag anomalous DNS, HTTP or reverse-shell patterns originating from camera IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/60190 | Third Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/84569 | Third Party AdvisoryVDB Entry |
| https://packetstormsecurity.com/files/cve/CVE-2013-2568/page1/ | Third Party AdvisoryVDB Entry |
| https://vulmon.com/vulnerabilitydetails?qid=CVE-2013-2568 | Third Party Advisory |
| https://www.coresecurity.com/advisories/zavio-ip-cameras-multiple-vulnerabilities | ExploitThird Party Advisory |
| http://www.securityfocus.com/bid/60190 | Third Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/84569 | Third Party AdvisoryVDB Entry |
| https://packetstormsecurity.com/files/cve/CVE-2013-2568/page1/ | Third Party AdvisoryVDB Entry |
| https://vulmon.com/vulnerabilitydetails?qid=CVE-2013-2568 | Third Party Advisory |
| https://www.coresecurity.com/advisories/zavio-ip-cameras-multiple-vulnerabilities | ExploitThird Party Advisory |
Track CVE-2013-2568 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2568), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.