Vulnerability record · CVE-2017-5174 · published 19 May 2017
CVE-2017-5174: Geutebruck IP Camera authentication bypass enabling remote code execution
GGeutebruck · Ip Camera G Cam Efd 2250 Firmware
Geutebruck IP Camera G-Cam/EFD-2250 firmware 1.11.0.12 contains an authentication bypass in which the file system architecture allows attackers to circumvent access controls. Successful bypass can lead to remote code execution on the camera. The flaw is remotely reachable without credentials, making exposed cameras a serious risk.
Description
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has been identified. The existing file system architecture could allow attackers to bypass the access control that may allow remote code execution.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, high EPSS, and public exploit code make this an urgent patch-or-isolate case despite no KEV listing.
What it is
Geutebruck IP Camera G-Cam/EFD-2250 firmware 1.11.0.12 contains an authentication bypass in which the file system architecture allows attackers to circumvent access controls. Successful bypass can lead to remote code execution on the camera. The flaw is remotely reachable without credentials, making exposed cameras a serious risk.
Impact
An unauthenticated attacker gains full control of the affected camera, with high confidentiality, integrity and availability impact, and can execute code on the device. This can expose video feeds and provide a foothold into the camera's network segment.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges or user interaction required (PR:N, UI:N), so any host that can reach the camera's web or management interface can attempt it. No authentication is needed to trigger the bypass.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.52 (98.9th percentile) and a public Exploit-DB entry (41360) exists, indicating exploit code is publicly available. No ransomware association is documented.
What to do
- Apply the vendor firmware update for G-Cam/EFD-2250 that addresses the authentication bypass; consult the Geutebruck advisory referenced by ICSA-17-045-02 for the fixed version.
- If patching is not immediately possible, remove cameras from direct internet exposure and place them behind a firewall or VPN with strict allowlists.
- Segment camera networks from business and user networks, and block inbound access to camera management interfaces from untrusted zones.
- Change default credentials and disable unused services on the camera as a defense-in-depth measure.
- Monitor vendor and ICS-CERT advisories for updated guidance on this product line.
Detection
- Review camera and perimeter logs for unauthenticated requests to management or file-system paths that precede unexpected process execution or configuration changes.
- Alert on new or unusual outbound connections from camera IP addresses, which may indicate post-exploitation activity.
- Use network monitoring to detect exploit traffic matching public PoC patterns against the camera's web interface.
- Audit camera firmware versions across the estate to identify devices still running 1.11.0.12 or other unpatched builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/96209 | Third Party AdvisoryVDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSA-17-045-02 | Third Party AdvisoryUS Government Resource |
| https://www.exploit-db.com/exploits/41360/ | |
| http://www.securityfocus.com/bid/96209 | Third Party AdvisoryVDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSA-17-045-02 | Third Party AdvisoryUS Government Resource |
| https://www.exploit-db.com/exploits/41360/ |
Track CVE-2017-5174 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-5174), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.