CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-29192

Medium Severity
SVRS
30/100

CVSSv3
NA/10

EPSS
0.0003/1

CVE-2024-29192 is a Cross-Site Request Forgery (CSRF) vulnerability in go2rtc versions 1.8.5 and earlier, a camera streaming application. This flaw allows an attacker to potentially modify the application's configuration and execute arbitrary commands by tricking a user into visiting a malicious webpage while authenticated to go2rtc. The /api/config endpoint, intended for local configuration changes, lacks CSRF protection. Although the SVRS score is 30, the vulnerability could be exploited if go2rtc is configured in a specific manner. If exploited, an attacker can add malicious streams that trigger arbitrary command execution on the server. This security risk highlights the importance of proper configuration and CSRF protection mechanisms. While the CVSS score is 0, the potential for arbitrary command execution makes patching and secure configurations essential. The fix adds a warning about secure API access.

In The Wild
2024-04-04

2024-04-04

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-29192 | AlexxIT go2rtc up to 1.8.5 /api/config cross-site request forgery (GHSL-2023-205)
vuldb.com2025-04-08
CVE-2024-29192 | AlexxIT go2rtc up to 1.8.5 /api/config cross-site request forgery (GHSL-2023-205) | A vulnerability was found in AlexxIT go2rtc up to 1.8.5 and classified as problematic. This issue affects some unknown processing of the file /api/config. The manipulation leads to cross-site request forgery. The identification of this vulnerability is CVE-2024-29192. The attack may be initiated remotely. There
vuldb.com
rss
forum
news

Social Media

No tweets found for this CVE

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://github.com/AlexxIT/go2rtc/commit/8793c3636493c5efdda08f3b5ed5c6e1ea594fd9
[email protected]https://securitylab.github.com/advisories/GHSL-2023-205_GHSL-2023-207_go2rtc/
GITHUBhttps://securitylab.github.com/advisories/GHSL-2023-205_GHSL-2023-207_go2rtc/

CWE Details

CWE IDCWE NameDescription
CWE-352Cross-Site Request Forgery (CSRF)The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence