Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q6gq-vxg6-9m9p

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can exploit this by sending a POST request with the 'passkey' parameter set to '1234', allowing them to access the web control panel.

COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can exploit this by sending a POST request with the 'passkey' parameter set to '1234', allowing them to access the web control panel.

EPSS

Процентиль: 18%
0.00059
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-1392

Связанные уязвимости

nvd
2 месяца назад

COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can exploit this by sending a POST request with the 'passkey' parameter set to '1234', allowing them to access the web control panel.

EPSS

Процентиль: 18%
0.00059
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-1392