Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3xp-rqx4-ch6m

Опубликовано: 06 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 9.8

Описание

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.

EPSS

Процентиль: 69%
0.00616
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 месяца назад

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.

EPSS

Процентиль: 69%
0.00616
Низкий

8.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-331