Vulnerability record · CVE-2021-3577 · published 12 November 2021
CVE-2021-3577: Motorola Binatone Hubble cameras command injection allows unauthenticated RCE
Binatoneglobal · Halo\+ Camera Firmware
Several Motorola-branded Binatone Hubble camera firmware images contain an OS command injection flaw (CWE-78) combined with incorrect authorization (CWE-863). An attacker on the same network segment can reach the device without credentials and execute commands, which matters because these are consumer cameras often placed on home and small-office LANs.
Description
An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityUnauthenticated adjacent-network RCE with high CVSS impact and very high EPSS, though exploitation is limited to the local network and no KEV or public exploit is documented.
What it is
Several Motorola-branded Binatone Hubble camera firmware images contain an OS command injection flaw (CWE-78) combined with incorrect authorization (CWE-863). An attacker on the same network segment can reach the device without credentials and execute commands, which matters because these are consumer cameras often placed on home and small-office LANs.
Impact
An attacker gains unauthenticated remote code execution on the camera, giving full control of the device (high confidentiality, integrity and availability impact per the CVSS vector). This can be used to pivot further into the local network or to spy on the camera's environment.
Attack surface
The CVSS vector is AV:A (adjacent network), PR:N and UI:N, so the flaw is reachable from the same network segment with no authentication and no user interaction. It is not described as remotely exploitable over the internet.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.60 probability over 30 days (99th percentile), and the only references are vendor advisories with no public exploit tag.
What to do
- Apply the vendor firmware update from the Binatone Global security advisory for each affected camera model.
- If no patch is available for a model, isolate the camera on a dedicated VLAN or guest network with no access to other LAN hosts.
- Block inbound access to camera management and streaming ports from untrusted network segments.
- Replace end-of-support cameras that will not receive firmware fixes.
- Monitor vendor advisory page for updated firmware releases.
Detection
- Monitor camera network traffic for unexpected outbound connections or command-and-control patterns from camera IPs.
- Alert on anomalous processes or shell activity on camera devices where host telemetry is available.
- Watch for scanning or connection attempts to camera management ports from other hosts on the same LAN.
- Review camera firmware versions against the vendor advisory to identify unpatched devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
21 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://binatoneglobal.com/security-advisory/ | Vendor Advisory |
| https://binatoneglobal.com/security-advisory/ | Vendor Advisory |
Track CVE-2021-3577 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-3577), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.