Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r5g5-cgx4-4r36

Опубликовано: 01 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.

EPSS

Процентиль: 29%
0.00107
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-290

Связанные уязвимости

nvd
7 месяцев назад

An authentication bypass vulnerability exists in AVTECH IP camera, DVR, and NVR devices’ streamd web server. The strstr() function is used to identify ".cab" requests, allowing any URL containing ".cab" to bypass authentication and access protected endpoints.

EPSS

Процентиль: 29%
0.00107
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-290