Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cx3r-78v3-hh67

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploiting the /overview.asp endpoint. Attackers can access sensitive information, including login credentials and DVR settings, by submitting a GET request to this endpoint.

COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploiting the /overview.asp endpoint. Attackers can access sensitive information, including login credentials and DVR settings, by submitting a GET request to this endpoint.

EPSS

Процентиль: 26%
0.0009
Низкий

8.7 High

CVSS4

Дефекты

CWE-306

Связанные уязвимости

nvd
2 месяца назад

COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploiting the /overview.asp endpoint. Attackers can access sensitive information, including login credentials and DVR settings, by submitting a GET request to this endpoint.

EPSS

Процентиль: 26%
0.0009
Низкий

8.7 High

CVSS4

Дефекты

CWE-306