← Vulnerability feed

Vulnerability record · CVE-2017-8230 · published 3 July 2019

CVE-2017-8230: Amcrest ipm-721s firmware permissions and access controls vulnerability

Amcrest · Ipm 721s Firmware

On Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices, the users on the device are divided into 2 groups "admin" and "user". However, as a part of security analysis it was identified that a low privileged user who belongs to the "user" group and who has access to login in to the web administrative interface of the device can add a new administrative user to the interface using HTTP APIs provided by the device and perform all the actions as an administrative user by using that account. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable functions that performs the various action described in HTTP APIs. If one opens this binary in IDA-pro one will notice that this follows a ARM little endian format. The function at address 0x00429084 in IDA pro is the one that processes the HTTP API request for "addUser" action. If one traces the calls to this function, it can be clearly seen that the function sub_ 41F38C at address 0x0041F588 parses the call received from the browser and passes it to the "addUser" function without any authorization check.

8.8 CVSS 3.0 High EPSS 1.7% · top 24.3% CWE-264 · Permissions and access controls
8.8CVSS 3.0 base score, v2 4.0
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

On Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices, the users on the device are divided into 2 groups "admin" and "user". However, as a part of security analysis it was identified that a low privileged user who belongs to the "user" group and who has access to login in to the web administrative interface of the device can add a new administrative user to the interface using HTTP APIs provided by the device and perform all the actions as an administrative user by using that account. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable functions that performs the various action described in HTTP APIs. If one opens this binary in IDA-pro one will notice that this follows a ARM little endian format. The function at address 0x00429084 in IDA pro is the one that processes the HTTP API request for "addUser" action. If one traces the calls to this function, it can be clearly seen that the function sub_ 41F38C at address 0x0041F588 parses the call received from the browser and passes it to the "addUser" function without any authorization check.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-8230 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-13719Amcrest ipm-721s firmware memory buffer overflow vulnerabilityThe Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various functionalities of the camera…EPSS 4.5%9.8CVE-2017-8226Amcrest ipm-721s firmware hard-coded credentials vulnerabilityAmcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who rev…EPSS 3.8%9.8CVE-2017-8227Amcrest ipm-721s firmware vulnerabilityAmcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are detected us…EPSS 4.1%9.8CVE-2017-8229Amcrest IPM-721S camera exposes admin credentials via unauthenticated file downloadAmcrest IPM-721S firmware V2.420.AC00.16.R.20160909 maps the /current_config path to the on-device /mnt/mtd/Config directory, which holds account and…EPSS 74%analysed8.8CVE-2017-8228Amcrest ipm-721s firmware permissions and access controls vulnerabilityAmcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough ve…EPSS 2.6%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed6.6CVE-2015-1769Windows Mount Manager symlink mishandling allows local privilege escalationThe Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core…KEVEPSS 4.1%analysed7.8CVE-2016-3643SolarWinds Virtualization Manager sudo misconfiguration privilege escalationSolarWinds Virtualization Manager 6.3.1 and earlier ship with a misconfigured sudo policy that lets a local user run privileged commands, as shown by…KEVEPSS 3.7%analysed

Source: NIST National Vulnerability Database (record CVE-2017-8230), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.