Vulnerability record · CVE-2017-9828 · published 23 June 2017
CVE-2017-9828: VIVOTEK Network Cameras shell command injection in testserver.cgi
Vivotek · Network Camera Ib8369 Firmware
The testserver.cgi endpoint in the web service of most VIVOTEK Network Cameras passes the senderemail parameter to a shell without sanitization, allowing OS command injection. An unauthenticated remote attacker can run arbitrary shell commands as root, making this a full device compromise. The flaw is confirmed on IB8369, FD8164 and FD816BA, and other models with similar firmware may also be affected.
Description
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected. An attack uses shell metacharacters in the senderemail parameter.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote root command execution with a CVSS score of 9.8 and very high EPSS probability makes this a top-priority exposure for any internet- or network-reachable VIVOTEK camera.
What it is
The testserver.cgi endpoint in the web service of most VIVOTEK Network Cameras passes the senderemail parameter to a shell without sanitization, allowing OS command injection. An unauthenticated remote attacker can run arbitrary shell commands as root, making this a full device compromise. The flaw is confirmed on IB8369, FD8164 and FD816BA, and other models with similar firmware may also be affected.
Impact
An attacker gains root-level command execution on the camera, enabling full control of the device, data theft, and use as a pivot into the network. Because commands run as root, persistence and firmware-level tampering are possible.
Attack surface
Reachable over the network through the camera's HTTP web service via a crafted request to /cgi-bin/admin/testserver.cgi using shell metacharacters in the senderemail parameter. The CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.82455, 99.6th percentile), indicating strong likelihood of exploitation activity. The only references are third-party advisories describing the technique, with no vendor advisory or exploit tag in the record.
What to do
- Apply the vendor firmware update for affected VIVOTEK camera models; if no patch is available, isolate or replace the devices.
- Block or restrict external and untrusted access to camera web interfaces, especially /cgi-bin/admin/testserver.cgi, using firewall rules or a management VLAN.
- Disable or restrict the camera web service where it is not required, and change default credentials.
- Monitor vendor advisories for the affected models and confirm firmware versions against the vendor's fixed release.
- Segment cameras from production networks so a compromised device cannot reach other systems.
Detection
- Inspect HTTP request logs and IDS/IPS alerts for requests to /cgi-bin/admin/testserver.cgi, particularly with shell metacharacters in the senderemail parameter.
- Monitor camera processes and outbound connections for unexpected shell activity or command-and-control traffic.
- Alert on unusual outbound traffic from camera IP addresses, which normally should not initiate arbitrary connections.
- Check camera firmware versions against the vendor's fixed release to identify unpatched devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://blog.cal1.cn/post/An%20easy%20way%20to%20pwn%20most%20of%20the%20vivotek%20network%20cameras | Third Party Advisory |
| https://blog.cal1.cn/post/An%20easy%20way%20to%20pwn%20most%20of%20the%20vivotek%20network%20cameras | Third Party Advisory |
Track CVE-2017-9828 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-9828), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.