Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-36925

Опубликовано: 06 янв. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.

EPSS

Процентиль: 70%
0.00623
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 9.8
github
около 1 месяца назад

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.

EPSS

Процентиль: 70%
0.00623
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-331