Showing posts with label Edimax. Show all posts
Showing posts with label Edimax. Show all posts

Wednesday, March 19, 2025

CISA Adds Edimax Vulnerability to KEV Catalog – 3-19-25

Today CISA announced that it had added an OS command injection vulnerability in the Edimax IC-7100 IP Camera to their Known Exploited Vulnerabilities (KEV) catalog. CISA had previously disclosed the vulnerability, noting at the time that Edimax had not responded to CISA’s coordination attempts. Akami reports that they have been seeing the vulnerability exploited in the wild since September 2024 and noting that proof-of-concept code has been available since June 2023. Apparently, the reason that Edimax has not been responding to vulnerability coordination efforts is that the IC-7100 IP Camera has been end-of-life for quite some time. Unfortunately, Akami surmises that the vulnerability exists in other IoT products from Edimax.

CISA is requiring federal agencies that have the affected Edimax camera to apply “mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.” A deadline of March 9th, 2025 has been provided.

Tuesday, March 4, 2025

Review – 8 Advisories Published – 3-4 -25

Today CISA’s NCCIC-ICS published eight control system security advisories for products from Edimax, GMOD, Delta Electronics, Hitachi Energy (3), Keysight, and Carrier.

Advisories

Edimax Advisory - This advisory describes an OS command injection vulnerability in the Edimax IC-7100 IP Camera.

GMOD Advisory - This advisory describes four vulnerabilities in the GMOD Apollo genome annotation editor.

Delta Advisory - This advisory describes a heap-based buffer overflow vulnerability in the Delta CNCSoft-G2 human-machine interface.

Hitachi Energy Advisory #1 - This advisory describes an improper validation of certificate with host mismatch vulnerability in the Hitachi Energy XMC20, ECST, and UNEM products.

Hitachi Energy Advisory #2 - This advisory describes relative path traversal vulnerability in the Hitachi Energy XMC20 multiservice communication platform.

Hitachi Energy Advisory #3 - This advisory discusses an uncontrolled search path element vulnerability in the Hitachi Energy MACH PS700 control system.

Keysight Advisory - This advisory describes four vulnerabilities in the Keysight Ixia Vision Product Family.

 

For more information on these advisories, including links to earlier discussions about some of these reported advisories and an apparently duplicate CISA advisory, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/8-advisories-published-3-4-25 - subscription required.

 
/* Use this with templates/template-twocol.html */