Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x9hg-4fh7-crh8

Опубликовано: 13 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.

JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.

EPSS

Процентиль: 79%
0.01272
Низкий

8.7 High

CVSS4

Дефекты

CWE-22

Связанные уязвимости

nvd
около 1 месяца назад

JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.

EPSS

Процентиль: 79%
0.01272
Низкий

8.7 High

CVSS4

Дефекты

CWE-22