← Vulnerability feed

Vulnerability record · CVE-2021-3577 · published 12 November 2021

CVE-2021-3577: Motorola Binatone Hubble cameras command injection allows unauthenticated RCE

Binatoneglobal · Halo\+ Camera Firmware

Several Motorola-branded Binatone Hubble camera firmware images contain an OS command injection flaw (CWE-78) combined with incorrect authorization (CWE-863). An attacker on the same network segment can reach the device without credentials and execute commands, which matters because these are consumer cameras often placed on home and small-office LANs.

8.8 CVSS 3.1 High EPSS 60% · top 0.9% CWE-78 · OS command injectionCWE-863 · Incorrect authorization
8.8CVSS 3.1 base score, v2 5.8
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
21Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated adjacent-network RCE with high CVSS impact and very high EPSS, though exploitation is limited to the local network and no KEV or public exploit is documented.

What it is

Several Motorola-branded Binatone Hubble camera firmware images contain an OS command injection flaw (CWE-78) combined with incorrect authorization (CWE-863). An attacker on the same network segment can reach the device without credentials and execute commands, which matters because these are consumer cameras often placed on home and small-office LANs.

Impact

An attacker gains unauthenticated remote code execution on the camera, giving full control of the device (high confidentiality, integrity and availability impact per the CVSS vector). This can be used to pivot further into the local network or to spy on the camera's environment.

Attack surface

The CVSS vector is AV:A (adjacent network), PR:N and UI:N, so the flaw is reachable from the same network segment with no authentication and no user interaction. It is not described as remotely exploitable over the internet.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.60 probability over 30 days (99th percentile), and the only references are vendor advisories with no public exploit tag.

What to do

  • Apply the vendor firmware update from the Binatone Global security advisory for each affected camera model.
  • If no patch is available for a model, isolate the camera on a dedicated VLAN or guest network with no access to other LAN hosts.
  • Block inbound access to camera management and streaming ports from untrusted network segments.
  • Replace end-of-support cameras that will not receive firmware fixes.
  • Monitor vendor advisory page for updated firmware releases.

Detection

  • Monitor camera network traffic for unexpected outbound connections or command-and-control patterns from camera IPs.
  • Alert on anomalous processes or shell activity on camera devices where host telemetry is available.
  • Watch for scanning or connection attempts to camera management ports from other hosts on the same LAN.
  • Review camera firmware versions against the vendor advisory to identify unpatched devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

21 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-3577 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-3787Binatoneglobal halo\+ camera firmware vulnerabilityA vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with local access to obtain the MQTT crede…EPSS 0.17%6.8CVE-2021-3788Binatoneglobal halo\+ camera firmware improper authentication vulnerabilityAn exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthoriz…EPSS 0.24%6.5CVE-2021-3790Binatoneglobal halo\+ camera firmware stack-based buffer overflow vulnerabilityA buffer overflow was reported in the local web server of some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker …EPSS 0.40%6.5CVE-2021-3791Binatoneglobal halo\+ camera firmware sensitive information in log file vulnerabilityAn information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on…EPSS 0.42%5.3CVE-2021-3792Binatoneglobal halo\+ camera firmware cleartext transmission vulnerabilitySome device communications in some Motorola-branded Binatone Hubble Cameras with backend Hubble services are not encrypted which could lead to the co…EPSS 0.49%5.3CVE-2021-3793Binatoneglobal halo\+ camera firmware vulnerabilityAn improper access control vulnerability was reported in some Motorola-branded Binatone Hubble Cameras which could allow an unauthenticated attacker …EPSS 0.70%4.6CVE-2021-3789Binatoneglobal halo\+ camera firmware insufficiently protected credentials vulnerabilityAn information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical acce…EPSS 0.09%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed

Source: NIST National Vulnerability Database (record CVE-2021-3577), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.