KEVIntel
9.3
CVSS
Critical

CVE-2025-1316

PUBLISHED

Edimax IC-7100 IP Camera OS Command Injection

Exploited in the wild Remote Low complexity No user interaction
Vendor
Edimax
Product
IC-7100 IP Camera
Published
Mar 04, 2025
EPSS

Description

Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device

cisa

CVSS scores

CVSS v4.0 9.3 Critical

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2025-03-19 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 19, 2025

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel