BEWARD N100 H.264 VGA IP Camera M2.1.6 Arbitrary File Disclosure
Posted by deepcore on February 5, 2019 – 1:35 pm
BEWARD N100 H.264 VGA IP Camera version M2.1.6 suffers from an authenticated file disclosure vulnerability. Input passed via the ‘READ.filePath’ parameter in fileread script is not properly verified before being used to read files. This can be exploited to disclose the contents of arbitrary files via absolute path or via the SendCGICMD API.
Post a reply
You must be logged in to post a comment.