← Vulnerability feed

Vulnerability record · CVE-2013-2568 · published 29 January 2020

CVE-2013-2568: Zavio IP Cameras command injection in wireless_mft.cgi ap parameter

Zavio · F3105 Firmware

Zavio IP Cameras through firmware 1.6.3 pass the ap parameter of /cgi-bin/mft/wireless_mft.cgi to a shell without sanitization, allowing OS command injection. The flaw is remotely reachable and unauthenticated per the CVSS vector, so any exposed camera can be turned into an execution point on the local network.

9.8 CVSS 3.1 Critical EPSS 49% · top 1.2% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with CVSS 9.8 and high EPSS on internet-exposed IoT devices makes this an urgent fix despite the absence of KEV listing.

What it is

Zavio IP Cameras through firmware 1.6.3 pass the ap parameter of /cgi-bin/mft/wireless_mft.cgi to a shell without sanitization, allowing OS command injection. The flaw is remotely reachable and unauthenticated per the CVSS vector, so any exposed camera can be turned into an execution point on the local network.

Impact

An attacker can execute arbitrary commands on the camera with the privileges of the CGI process, gaining full control of the device and a foothold for lateral movement into the camera's network segment.

Attack surface

Reached over the network via an HTTP request to /cgi-bin/mft/wireless_mft.cgi with a crafted ap parameter; the CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is 0.485 (98.8th percentile) and a Core Security advisory is tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Zavio camera firmware beyond 1.6.3 if a fixed release is available; the record does not name a patched version, so confirm with the vendor.
  • If no fix exists, isolate cameras on a dedicated VLAN with no route to management or user networks.
  • Block or restrict external and cross-segment access to /cgi-bin/mft/wireless_mft.cgi and the camera web interface.
  • Disable or replace end-of-life Zavio F3105/F312A units that cannot be patched.
  • Change default credentials and disable unused services such as UPnP and remote access.

Detection

  • Monitor HTTP request logs and IDS/IPS for requests to /cgi-bin/mft/wireless_mft.cgi with shell metacharacters in the ap parameter.
  • Alert on unexpected outbound connections or new processes spawned by the camera's CGI/web service.
  • Baseline camera traffic and flag anomalous DNS, HTTP or reverse-shell patterns originating from camera IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-2568 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2013-2570Zavio f3105 firmware os command injection vulnerabilityA Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the b…EPSS 27%7.5CVE-2013-2569Zavio f3105 firmware improper authentication vulnerabilityA Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could…EPSS 31%7.5CVE-2013-2567Zavio f3105 firmware hard-coded credentials vulnerabilityAn Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.c…EPSS 15%8.8CVE-2026-86950Apple ipados out-of-bounds write vulnerabilityAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, …KEV8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2013-2568), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.