Back

Command Execution Due To Unsanitized Input In LifeShield DIY HD Video Doorbell

Publication date: February 2nd, 2021


CVE ID:
CVE-2020-8101
CVSS scrore:
6.9 - CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L
Affected vendors:
ADT
Affected products:
LifeShield DIY HD Video Doorbell
Vulnerability details:

Improper Neutralization of Special Elements used in a Command (‘Command Injection’) vulnerability in HTTP interface of ADT LifeShield DIY HD Video Doorbell allows an attacker on the same network to execute commands on the device. This issue affects: ADT LifeShield DIY HD Video Doorbell version 1.0.02R09 and prior versions.

Credit:
Bitdefender Labs