← Vulnerability feed

Vulnerability record · CVE-2017-5174 · published 19 May 2017

CVE-2017-5174: Geutebruck IP Camera authentication bypass enabling remote code execution

GGeutebruck · Ip Camera G Cam Efd 2250 Firmware

Geutebruck IP Camera G-Cam/EFD-2250 firmware 1.11.0.12 contains an authentication bypass in which the file system architecture allows attackers to circumvent access controls. Successful bypass can lead to remote code execution on the camera. The flaw is remotely reachable without credentials, making exposed cameras a serious risk.

9.8 CVSS 3.0 Critical EPSS 52% · top 1.1% CWE-288 · Authentication bypass via alternate path
9.8CVSS 3.0 base score, v2 7.5
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has been identified. The existing file system architecture could allow attackers to bypass the access control that may allow remote code execution.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required, high EPSS, and public exploit code make this an urgent patch-or-isolate case despite no KEV listing.

What it is

Geutebruck IP Camera G-Cam/EFD-2250 firmware 1.11.0.12 contains an authentication bypass in which the file system architecture allows attackers to circumvent access controls. Successful bypass can lead to remote code execution on the camera. The flaw is remotely reachable without credentials, making exposed cameras a serious risk.

Impact

An unauthenticated attacker gains full control of the affected camera, with high confidentiality, integrity and availability impact, and can execute code on the device. This can expose video feeds and provide a foothold into the camera's network segment.

Attack surface

The vulnerability is network-reachable (AV:N) with no privileges or user interaction required (PR:N, UI:N), so any host that can reach the camera's web or management interface can attempt it. No authentication is needed to trigger the bypass.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at roughly 0.52 (98.9th percentile) and a public Exploit-DB entry (41360) exists, indicating exploit code is publicly available. No ransomware association is documented.

What to do

  • Apply the vendor firmware update for G-Cam/EFD-2250 that addresses the authentication bypass; consult the Geutebruck advisory referenced by ICSA-17-045-02 for the fixed version.
  • If patching is not immediately possible, remove cameras from direct internet exposure and place them behind a firewall or VPN with strict allowlists.
  • Segment camera networks from business and user networks, and block inbound access to camera management interfaces from untrusted zones.
  • Change default credentials and disable unused services on the camera as a defense-in-depth measure.
  • Monitor vendor and ICS-CERT advisories for updated guidance on this product line.

Detection

  • Review camera and perimeter logs for unauthenticated requests to management or file-system paths that precede unexpected process execution or configuration changes.
  • Alert on new or unusual outbound connections from camera IP addresses, which may indicate post-exploitation activity.
  • Use network monitoring to detect exploit traffic matching public PoC patterns against the camera's web interface.
  • Audit camera firmware versions across the estate to identify devices still running 1.11.0.12 or other unpatched builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-5174 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-20079Cisco Secure Firewall Management Center authentication bypass to rootCisco Secure Firewall Management Center (FMC) Software contains an authentication bypass caused by an improper system process created at boot time. A…KEVEPSS 88%analysed9.3CVE-2026-19490Citrix NetScaler ADC and Gateway authentication bypass via alternate pathNetScaler ADC and NetScaler Gateway contain an authentication bypass via an alternate path or channel (CWE-288). The flaw is remotely reachable witho…KEVEPSS 7.0%analysed8.2CVE-2026-18556N-able N-central authentication bypass via alternate pathN-able N-central contains an authentication bypass (CWE-288) that lets an attacker reach protected functionality through an alternate path or channel…KEVEPSS 7.9%analysed8.2CVE-2026-18577N-able N-central incomplete patch enables auth bypass and account takeoverAn incomplete fix for CVE-2026-18556 leaves an alternate-path authentication bypass in N-able N-central through version 2026.3.1. Because the origina…KEVEPSS 15%analysed7.5CVE-2026-1603Ivanti Endpoint Manager authentication bypass leaks stored credentialsIvanti Endpoint Manager before 2024 SU5 contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker reach a func…KEVEPSS 88%analysed9.8CVE-2026-24858Fortinet FortiCloud SSO authentication bypass across registered devicesA CWE-288 authentication bypass in Fortinet FortiAnalyzer, FortiManager, FortiNAC-F, FortiOS, FortiProxy and FortiWeb lets an attacker with a FortiCl…KEVEPSS 86%analysed9.3CVE-2026-23760SmarterMail password reset API authentication bypassSmarterMail builds prior to 9511 expose a force-reset-password endpoint that accepts anonymous requests and does not verify the current password or a…KEVEPSS 97%analysed9.2CVE-2025-34026Versa Concerto authentication bypass in Traefik proxy exposes admin endpointsVersa Concerto's Traefik reverse proxy configuration contains an authentication bypass (CWE-288) that lets an unauthenticated attacker reach administ…KEVEPSS 82%analysed

Source: NIST National Vulnerability Database (record CVE-2017-5174), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.