← Vulnerability feed

Vulnerability record · CVE-2019-8387 · published 8 May 2019

CVE-2019-8387: MASTER IPCAMERA01 thttpd component remote command execution

Barni · Master Ip Camera01 Firmware

MASTER IPCAMERA01 firmware version 3.3.4.2103 allows remote command execution through its thttpd component. The flaw is network-reachable and requires no authentication or user interaction, so any exposed camera can be attacked directly. The record gives no root-cause detail beyond the thttpd component, so the exact injection point is not documented here.

9.8 CVSS 3.0 Critical EPSS 56% · top 1.0%
9.8CVSS 3.0 base score, v2 7.5
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required, public exploit code and very high EPSS make this an urgent exposure for any reachable device.

What it is

MASTER IPCAMERA01 firmware version 3.3.4.2103 allows remote command execution through its thttpd component. The flaw is network-reachable and requires no authentication or user interaction, so any exposed camera can be attacked directly. The record gives no root-cause detail beyond the thttpd component, so the exact injection point is not documented here.

Impact

An attacker can execute arbitrary commands on the device, gaining full control of the camera and any data or network access it holds. With CVSS 9.8 across confidentiality, integrity and availability, the compromise is complete.

Attack surface

Reached over the network via the device's thttpd web service; the CVSS vector shows no privileges and no user interaction required. Any internet- or LAN-exposed MASTER IPCAMERA01 running 3.3.4.2103 is in scope.

Exploitation

Public exploit code exists in Packet Storm and Exploit-DB, and EPSS is 0.55721 (99th percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV, so no confirmed in-the-wild campaign is recorded here.

What to do

  • Patch or replace MASTER IPCAMERA01 firmware 3.3.4.2103; if no fixed firmware exists, retire or isolate the device.
  • Remove cameras from direct internet exposure and place them behind a VPN or firewall with strict allowlists.
  • Segment IoT cameras onto a dedicated VLAN with no access to corporate or management networks.
  • Disable or block the thttpd service where it is not required, and change default credentials.
  • Monitor vendor advisories for a fixed firmware release and apply it as soon as available.

Detection

  • Inspect thttpd access and error logs for command-injection patterns, shell metacharacters or unexpected process execution.
  • Alert on outbound connections from camera IPs to unknown hosts, especially shell or download activity.
  • Baseline normal camera traffic and flag anomalous HTTP requests or new listening services on the device.
  • Use network monitoring to detect exploit attempts matching the published Packet Storm and Exploit-DB proof-of-concept.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-8387 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2019-8387), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.