← Vulnerability feed

Vulnerability record · CVE-2017-8228 · published 3 July 2019

CVE-2017-8228: Amcrest ipm-721s firmware permissions and access controls vulnerability

Amcrest · Ipm 721s Firmware

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough verification when allowing the user to add a new camera to the user's account to ensure that the user actually owns the camera other than knowing the serial number of the camera. This can allow an attacker who knows the serial number to easily add another user's camera to an attacker's cloud account and control it completely. This is possible in case of any camera that is currently not a part of an Amcrest cloud account or has been removed from the user's cloud account. Also, another requirement for a successful attack is that the user should have rebooted the camera in the last two hours. However, both of these conditions are very likely for new cameras that are sold over the Internet at many ecommerce websites or vendors that sell the Amcrest products. The successful attack results in an attacker being able to completely control the camera which includes being able to view and listen on what the camera can see, being able to change the motion detection settings and also be able to turn the camera off without the user being aware of it. Note: The same attack can be executed using the Amcrest Cloud mobile application.

8.8 CVSS 3.0 High EPSS 2.6% · top 15.3% CWE-264 · Permissions and access controls
8.8CVSS 3.0 base score, v2 6.8
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough verification when allowing the user to add a new camera to the user's account to ensure that the user actually owns the camera other than knowing the serial number of the camera. This can allow an attacker who knows the serial number to easily add another user's camera to an attacker's cloud account and control it completely. This is possible in case of any camera that is currently not a part of an Amcrest cloud account or has been removed from the user's cloud account. Also, another requirement for a successful attack is that the user should have rebooted the camera in the last two hours. However, both of these conditions are very likely for new cameras that are sold over the Internet at many ecommerce websites or vendors that sell the Amcrest products. The successful attack results in an attacker being able to completely control the camera which includes being able to view and listen on what the camera can see, being able to change the motion detection settings and also be able to turn the camera off without the user being aware of it. Note: The same attack can be executed using the Amcrest Cloud mobile application.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-8228 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-13719Amcrest ipm-721s firmware memory buffer overflow vulnerabilityThe Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various functionalities of the camera…EPSS 4.5%9.8CVE-2017-8226Amcrest ipm-721s firmware hard-coded credentials vulnerabilityAmcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who rev…EPSS 3.8%9.8CVE-2017-8227Amcrest ipm-721s firmware vulnerabilityAmcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are detected us…EPSS 4.1%9.8CVE-2017-8229Amcrest IPM-721S camera exposes admin credentials via unauthenticated file downloadAmcrest IPM-721S firmware V2.420.AC00.16.R.20160909 maps the /current_config path to the on-device /mnt/mtd/Config directory, which holds account and…EPSS 74%analysed8.8CVE-2017-8230Amcrest ipm-721s firmware permissions and access controls vulnerabilityOn Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices, the users on the device are divided into 2 groups "admin" and "user". However, as a part of se…EPSS 1.7%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed6.6CVE-2015-1769Windows Mount Manager symlink mishandling allows local privilege escalationThe Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core…KEVEPSS 4.1%analysed7.8CVE-2016-3643SolarWinds Virtualization Manager sudo misconfiguration privilege escalationSolarWinds Virtualization Manager 6.3.1 and earlier ship with a misconfigured sudo policy that lets a local user run privileged commands, as shown by…KEVEPSS 3.7%analysed

Source: NIST National Vulnerability Database (record CVE-2017-8228), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.