CVE-2023-6321: Owletcare Cam 2 Firmware

High severity, CVSS 8.8. EPSS: 2.7% chance of exploitation in the next 30 days.

A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.

Affected products

  • Owletcare Cam 2 Firmware: before 4.2.10 (fixed in 4.2.10)
  • Owletcare Cam Firmware: before 4.2.11 (fixed in 4.2.11)
  • Throughtek Kalay Platform: affected versions not specified

Published 2024-05-15. Last modified 2026-06-17.