Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mfqx-6pfv-xp5p

Опубликовано: 24 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 8.8

Описание

Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to read arbitrary system files via the 'READ.filePath' parameter. Attackers can exploit the fileread script or SendCGICMD API to access sensitive files like /etc/passwd and /etc/issue by supplying absolute file paths.

Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to read arbitrary system files via the 'READ.filePath' parameter. Attackers can exploit the fileread script or SendCGICMD API to access sensitive files like /etc/passwd and /etc/issue by supplying absolute file paths.

EPSS

Процентиль: 14%
0.00045
Низкий

7.1 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 месяца назад

Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to read arbitrary system files via the 'READ.filePath' parameter. Attackers can exploit the fileread script or SendCGICMD API to access sensitive files like /etc/passwd and /etc/issue by supplying absolute file paths.

EPSS

Процентиль: 14%
0.00045
Низкий

7.1 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-22