{"resultsPerPage":36,"startIndex":0,"totalResults":36,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-05T21:50:01.430","vulnerabilities":[{"cve":{"id":"CVE-2008-5911","sourceIdentifier":"cve@mitre.org","published":"2009-01-20T16:00:00.203","lastModified":"2026-06-16T23:01:12.690","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server 11.x before 11.1.8 and 12.x before 12.0.1 allow remote attackers to (1) cause a denial of service via three crafted RTSP SETUP commands, or execute arbitrary code via (2) an NTLM authentication request with malformed base64-encoded data, (3) an RTSP DESCRIBE command, or (4) a DataConvertBuffer request."},{"lang":"es","value":"Múltiples desbordamientos de búfer en RealNetworks Helix Server y Helix Mobile Server v11.x anteriores a v11.1.8 y v12.x anteriores a v12.0.1 permite a atacantes remotos (1) provocar una denegación de servicio a través de tres comandos manipulados RTSP SETUP, o ejecutar código de su elección a través de (2) una petición de autenticación NTLM con datos malformados codificados en base64, (3) un comando RTSP DESCRIBE, o (4) una petición DataConvertBuffer."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-119"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:helix_server:11.0:*:*:*:*:*:*:*","matchCriteriaId":"A30A2490-21FC-4C0D-80A3-B89E6F58E93A"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:helix_server:12.0.0:*:*:*:*:*:*:*","matchCriteriaId":"0890EDD4-63FF-43EC-9EC4-852B34E00F51"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:helix_server_mobile:11.0:*:*:*:*:*:*:*","matchCriteriaId":"74F01F2C-036C-4B6E-B66D-F0870801D397"},{"vulnerable":true,"criteria":"cpe:2.3:a:realnetworks:helix_server_mobile:12.0.0:*:*:*:*:*:*:*","matchCriteriaId":"4CB773CC-C81C-424A-9493-4CAD2E0E8262"}]}]}],"references":[{"url":"http://docs.real.com/docs/security/SecurityUpdate121508HS.pdf","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://secunia.com/advisories/33360","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"http://www.securitytracker.com/id?1021498","source":"cve@mitre.org"},{"url":"http://www.securitytracker.com/id?1021499","source":"cve@mitre.org"},{"url":"http://www.securitytracker.com/id?1021500","source":"cve@mitre.org"},{"url":"http://www.securitytracker.com/id?1021501","source":"cve@mitre.org"},{"url":"http://www.vupen.com/english/advisories/2008/3521","source":"cve@mitre.org"},{"url":"http://docs.real.com/docs/security/SecurityUpdate121508HS.pdf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://secunia.com/advisories/33360","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.securitytracker.com/id?1021498","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id?1021499","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id?1021500","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securitytracker.com/id?1021501","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.vupen.com/english/advisories/2008/3521","source":"af854a3a-2127-422b-91ae-364da2661108"}],"evaluatorSolution":"Per: http://docs.real.com/docs/security/SecurityUpdate121508HS.pdf\r\n\r\nThe Fix:\r\nVersion 11.1.8 and Version 12.0.1 of the Helix Server and the Helix Mobile Server have been updated to ensure that the above\r\nvulnerabilities have been resolved.\r\n\r\nSOLUTION:\r\nThe vulnerability is resolved on the following platforms by installing Version 11.1.8 or Version 12.0.1 of the Helix Server and the Helix\r\nMobile Server. This only pertains to supported versions of the platforms listed below. The updated version will be available on your\r\nRealNetworks PAM site after 11:59 p.m. PST, on December 15, 2008.","evaluatorImpact":"Per: http://docs.real.com/docs/security/SecurityUpdate121508HS.pdf\r\n\r\nImpacted Products and Versions:\r\nHelix Server Version 11.x\r\nHelix Server Version 12.x\r\nHelix Mobile Server Version 11.x\r\nHelix Mobile Server Version 12.x"}},{"cve":{"id":"CVE-2017-8223","sourceIdentifier":"cve@mitre.org","published":"2017-04-25T20:59:00.350","lastModified":"2026-06-17T01:26:00.090","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via tcp/av0_1 or tcp/av0_0."},{"lang":"es","value":"En los dispositivos Wireless IP Camera (P2P) WIFICAM, un atacante puede utilizar el servidor RTSP en el puerto 10554/tcp para ver la transmisión sin autenticación a través de tcp/av0_1 o tcp/av0_0."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:wificam:wireless_ip_camera_\\(p2p\\)_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"D08E453A-E40A-48E7-9FC0-2CCEB7052644"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:wificam:wireless_ip_camera_\\(p2p\\):-:*:*:*:*:*:*:*","matchCriteriaId":"407AAB84-DC42-4CC9-A33F-4EBDE16C97E9"}]}]}],"references":[{"url":"http://seclists.org/fulldisclosure/2017/Mar/23","source":"cve@mitre.org","tags":["Exploit","Mailing List","Third Party Advisory"]},{"url":"https://pierrekim.github.io/blog/2017-03-08-camera-goahead-0day.html#pre-auth-info-leak-goahead","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"http://seclists.org/fulldisclosure/2017/Mar/23","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Mailing List","Third Party Advisory"]},{"url":"https://pierrekim.github.io/blog/2017-03-08-camera-goahead-0day.html#pre-auth-info-leak-goahead","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2017-10796","sourceIdentifier":"cve@mitre.org","published":"2017-07-02T22:29:00.230","lastModified":"2026-06-17T01:00:43.510","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL."},{"lang":"es","value":"En los dispositivos NC250 con firmware hasta la versión 1.2.1 build 170515 de TP-Link, cualquier persona puede visualizar vídeo y audio sin identificación  por medio de una URL rtsp://admin@yourip:554/h264_hd.sdp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:L/Au:N/C:P/I:N/A:N","baseScore":3.3,"accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.5,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:nc250_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.2.1","matchCriteriaId":"BA6B3F1C-6B2A-40CC-AAED-3DCA8E5E1E41"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:nc250:-:*:*:*:*:*:*:*","matchCriteriaId":"3C6A3B4E-F357-4E9F-A799-E58E0D593F19"}]}]}],"references":[{"url":"https://gist.github.com/elbauldelgeek/8f0f24c582f43f51a34b34420a385d75","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://gist.github.com/elbauldelgeek/8f0f24c582f43f51a34b34420a385d75","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2018-13115","sourceIdentifier":"cve@mitre.org","published":"2018-10-22T20:29:00.393","lastModified":"2026-06-17T01:38:52.820","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the camera stream. The RTSP server on port 7070 accepts the command STOP to stop streaming, and the command SETSSID to disconnect a user."},{"lang":"es","value":"La falta de un mecanismo de autenticación en KERUI Wifi Endoscope Camera (YPC99) permite que un atacante vea o bloquee la transmisión de la cámara. El servidor RTSP en el puerto 7070 acepta el comando STOP para detener la transmisión y el comando SETSSID para desconectar a un usuario."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-20"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:keruigroup:ypc99_firmware:*:*:*:*:*:*:*:*","matchCriteriaId":"A648BF89-A0F2-41C9-BFED-3A7CC6618E93"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:keruigroup:ypc99:-:*:*:*:*:*:*:*","matchCriteriaId":"5CCDD63D-DB5C-49A3-BAF3-362E09CCAE80"}]}]}],"references":[{"url":"https://utkusen.com/blog/multiple-vulnerabilities-on-kerui-endoscope-camera.html","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://utkusen.com/blog/multiple-vulnerabilities-on-kerui-endoscope-camera.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2018-19076","sourceIdentifier":"cve@mitre.org","published":"2018-11-07T18:29:05.070","lastModified":"2026-06-17T01:48:44.683","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The FTP and RTSP services make it easier for attackers to conduct brute-force authentication attacks, because failed-authentication limits apply only to HTTP (not FTP or RTSP)."},{"lang":"es","value":"Se ha descubierto un problema en dispositivos Foscam C2 con firmware del sistema 1.11.1.8 y firmware de aplicación 2.72.1.32, así como dispositivos Opticam i5 con firmware del sistema 1.5.2.11 y firmware de aplicación 2.21.1.128. Los servicios FTP y RTSP facilitan que los atacantes lleven a cabo ataques de autenticación por fuerza bruta, debido a que los límites de fallo de autenticación solo aplican a HTTP (no a FTP o RTSP)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opticam:i5_application_firmware:2.21.1.128:*:*:*:*:*:*:*","matchCriteriaId":"42E72BBD-5418-4C2C-B8EB-997224A0CA01"},{"vulnerable":true,"criteria":"cpe:2.3:o:opticam:i5_system_firmware:1.5.2.11:*:*:*:*:*:*:*","matchCriteriaId":"B9E1C7BD-97E3-41F9-BC4D-9C7320C471EE"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:opticam:i5:-:*:*:*:*:*:*:*","matchCriteriaId":"670C0300-3A68-4AC1-B659-7727FF92D8E6"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:foscam:c2_application_firmware:2.72.1.32:*:*:*:*:*:*:*","matchCriteriaId":"05CCF2DD-D69B-4518-B20A-376C98E2D02E"},{"vulnerable":true,"criteria":"cpe:2.3:o:foscam:c2_system_firmware:1.11.1.8:*:*:*:*:*:*:*","matchCriteriaId":"28AD15E7-51C8-4B2D-BCEB-8EF2AA0B61A5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:foscam:c2:-:*:*:*:*:*:*:*","matchCriteriaId":"107D84D0-9D16-4930-A312-38B7586B4B4F"}]}]}],"references":[{"url":"https://sintonen.fi/advisories/foscam-ip-camera-multiple-vulnerabilities.txt","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://sintonen.fi/advisories/foscam-ip-camera-multiple-vulnerabilities.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2013-1596","sourceIdentifier":"cve@mitre.org","published":"2020-01-24T18:15:11.973","lastModified":"2026-06-16T23:51:44.653","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554."},{"lang":"es","value":"Se presenta una Vulnerabilidad de Omisión de Autenticación en Vivotek PT7135 IP Camera versiones 0300a y 0400a, por medio de paquetes RTSP especialmente diseñados para el puerto TCP 554."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:vivotek:pt7135_firmware:0300a:*:*:*:*:*:*:*","matchCriteriaId":"C502822B-8D6A-4415-9BDF-87D871EA56A0"},{"vulnerable":true,"criteria":"cpe:2.3:o:vivotek:pt7135_firmware:0400a:*:*:*:*:*:*:*","matchCriteriaId":"45BA97A0-8179-415B-9DBA-0C9A83D78076"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:vivotek:pt7135:-:*:*:*:*:*:*:*","matchCriteriaId":"C775AFA9-DBFF-497B-B459-0F3D180DA195"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/59574","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/83945","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://github.com/offensive-security/exploitdb/blob/master/exploits/hardware/webapps/25139.txt","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://packetstormsecurity.com/files/cve/CVE-2013-1596","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.coresecurity.com/advisories/vivotek-ip-cameras-multiple-vulnerabilities","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/59574","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/83945","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://github.com/offensive-security/exploitdb/blob/master/exploits/hardware/webapps/25139.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://packetstormsecurity.com/files/cve/CVE-2013-1596","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.coresecurity.com/advisories/vivotek-ip-cameras-multiple-vulnerabilities","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2013-1602","sourceIdentifier":"cve@mitre.org","published":"2020-01-28T22:15:10.840","lastModified":"2026-06-16T23:51:45.430","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04_US, DCS-1130 1.03/1.04_US , DCS-2102 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-2121 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.0, DCS-7410 1.0, DCS-7510 1.0, and WCS-1100 1.02, which could let a malicious user obtain unauthorized access to video streams."},{"lang":"es","value":"Se presenta una vulnerabilidad de Divulgación de Información debido a una comprobación insuficiente de las cookies de autenticación para la sesión RTSP en D-Link DCS-5635 versión 1.01, DCS-1100L versión 1.04, DCS-1130L versión 1.04, DCS-1100 versiones 1.03/1.04_US, DCS-1130 versiones 1.03/1.04_US , DCS-2102 versiones 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-2121 versiones 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-3410 versión 1.02, DCS-5230 versión 1.02, DCS-5230L versión 1.02, DCS-6410 versión 1.0, DCS-7410 versión 1.0, DCS-7510 versión 1.0 y WCS-1100 versión 1.02, lo que podría permitir a un usuario malicioso obtener acceso no autorizado a transmisiones de video."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-3411_firmware:1.02:*:*:*:*:*:*:*","matchCriteriaId":"21E4F54E-78BD-4963-88C0-6B6F9D751C4B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-3411:-:*:*:*:*:*:*:*","matchCriteriaId":"5A0A639C-EC97-4CF6-B853-B9CE3EEDF399"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-3430_firmware:1.02:*:*:*:*:*:*:*","matchCriteriaId":"3595919A-23A4-42D7-BC22-9AA3E5F196E2"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-3430:-:*:*:*:*:*:*:*","matchCriteriaId":"0337488F-E15D-497E-855F-7719D4809433"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-5605_firmware:1.01:*:*:*:*:*:*:*","matchCriteriaId":"0C400977-3E3C-4010-8EFE-75F30180FF22"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-5605:-:*:*:*:*:*:*:*","matchCriteriaId":"8B92CB5D-CD8E-4768-91CE-C3497C8EA58A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-5635_firmware:1.01:*:*:*:*:*:*:*","matchCriteriaId":"76933BB0-E0C2-4F81-9B28-879EDAC49302"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-5635:-:*:*:*:*:*:*:*","matchCriteriaId":"CCFFD6C7-9379-4197-B447-1C755E6636AB"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-1100l_firmware:1.04:*:*:*:*:*:*:*","matchCriteriaId":"E0FD5F42-72DD-47F4-ABDD-E0E4D0D1754A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-1100l:-:*:*:*:*:*:*:*","matchCriteriaId":"70D1E7AB-C4EA-4B97-B788-944244777CFF"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-1130l_firmware:1.04:*:*:*:*:*:*:*","matchCriteriaId":"1B09CDBD-7DC9-4E4C-9FD6-3500C56D0B3E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-1130l:-:*:*:*:*:*:*:*","matchCriteriaId":"C6DF5842-F02E-4076-9B26-A3CC1EEBC94E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-1100_firmware:1.03:*:*:*:*:*:*:*","matchCriteriaId":"5A26476D-57A8-481C-80CB-80CC238F083A"},{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-1100_firmware:1.04:*:*:*:*:*:*:*","matchCriteriaId":"AD48A2EC-52EB-4C4B-B1ED-EC87822EDF5C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-1100:-:*:*:*:*:*:*:*","matchCriteriaId":"704F9608-72CE-49C0-B7D2-F2FE84DF0C74"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-1130_firmware:1.03:*:*:*:*:*:*:*","matchCriteriaId":"E5A39F0C-8E3B-41AA-8E1D-E2DABB0A4CCC"},{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-1130_firmware:1.04:*:*:*:*:*:*:*","matchCriteriaId":"EA9B1618-9862-470A-AA4D-02A779B314A1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-1130:-:*:*:*:*:*:*:*","matchCriteriaId":"33A388EC-275D-4180-83E2-AD73F7EEB54F"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-2102_firmware:1.05:*:*:*:*:*:*:*","matchCriteriaId":"28CE404D-2DFF-4203-8954-FA579EF5924B"},{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-2102_firmware:1.06:*:*:*:*:*:*:*","matchCriteriaId":"309BB5E5-5664-447B-B2C0-DCE54B0FDC2F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-2102:-:*:*:*:*:*:*:*","matchCriteriaId":"78CD04CA-964A-4D74-B30E-7DC53E1858B6"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-2121_firmware:1.05:*:*:*:*:*:*:*","matchCriteriaId":"C3435DC0-44C2-440D-9C56-39EC06782BBC"},{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-2121_firmware:1.06:*:*:*:*:*:*:*","matchCriteriaId":"631443E3-859B-439D-879E-C342B514BF33"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-2121:-:*:*:*:*:*:*:*","matchCriteriaId":"FC1DE485-2705-4394-BC93-0BE99FE02F12"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-3410_firmware:1.02:*:*:*:*:*:*:*","matchCriteriaId":"1DC3F994-76E7-487C-A144-FC6C5AFDC5D9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-3410:-:*:*:*:*:*:*:*","matchCriteriaId":"4558EBD8-5FB0-487B-88E6-17E76B2B68BC"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-5230_firmware:1.02:*:*:*:*:*:*:*","matchCriteriaId":"117E4B04-541F-4398-B644-959329FF45E5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-5230:-:*:*:*:*:*:*:*","matchCriteriaId":"A17CC0BD-D224-4A30-A8CF-07E469F4BFA4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-5230l_firmware:1.02:*:*:*:*:*:*:*","matchCriteriaId":"5265C1F6-0246-4AF4-B348-86D3F8C95C0D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-5230l:-:*:*:*:*:*:*:*","matchCriteriaId":"94FFCE95-2A81-465F-B4EB-3B1BD687D87F"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-6410_firmware:1.00:*:*:*:*:*:*:*","matchCriteriaId":"2915F59C-512F-44B7-BB67-B699B622C055"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-6410:-:*:*:*:*:*:*:*","matchCriteriaId":"994CFC4C-7EC2-450A-9E05-940EE3CBA9D5"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-7410_firmware:1.00:*:*:*:*:*:*:*","matchCriteriaId":"4DDC8CC0-F1B5-4EA4-A822-50FA02476365"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-7410:-:*:*:*:*:*:*:*","matchCriteriaId":"7AC168D7-AFFD-44A9-8CB7-29E1EDF0849A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-7510_firmware:1.00:*:*:*:*:*:*:*","matchCriteriaId":"4466E781-46D0-4A55-9136-3842E93C228A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-7510:-:*:*:*:*:*:*:*","matchCriteriaId":"EF686286-DFA4-49CE-BF64-D6BA849FDCD4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:wcs-1100_firmware:1.00:*:*:*:*:*:*:*","matchCriteriaId":"113F0277-63F1-4623-B668-88865ADFAD83"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:wcs-1100:-:*:*:*:*:*:*:*","matchCriteriaId":"D06ED3F1-B59E-447F-B4E6-D95FB834A6C1"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/59569","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/83942","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://packetstormsecurity.com/files/cve/CVE-2013-1602","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.coresecurity.com/advisories/d-link-ip-cameras-multiple-vulnerabilities","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/59569","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/83942","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://packetstormsecurity.com/files/cve/CVE-2013-1602","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.coresecurity.com/advisories/d-link-ip-cameras-multiple-vulnerabilities","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2013-1603","sourceIdentifier":"cve@mitre.org","published":"2020-01-28T22:15:10.917","lastModified":"2026-06-16T23:51:45.573","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU, DCS-2102 1.06_FR, DCS-2102 1.06, DCS-2102 1.05_RU, DCS-1130L 1.04, DCS-1130 1.04_US, DCS-1130 1.03, DCS-1100L 1.04, DCS-1100 1.04_US, and DCS-1100 1.03 due to hard-coded credentials that serve as a backdoor, which allows remote attackers to access the RTSP video stream."},{"lang":"es","value":"Se presenta una vulnerabilidad de Autenticación en D-LINK WCS-1100 versión 1.02, TESCO DCS-2121 versión 1.05_TESCO, TESCO DCS-2102 versión 1.05_TESCO, DCS-7510 versión 1.00, DCS-7410 versión 1.00, DCS-6410 versión 1.00, DCS-5635 versión 1.01, DCS-5605 versión 1.01, DCS-5230L versión 1.02, DCS-5230 versión 1.02, DCS-3430 versión 1.02, DCS-3411 versión 1.02, DCS-3410 versión 1.02, DCS-2121 versión 1.06_FR, DCS-2121 versión 1.06, DCS-2121 versión 1.05_RU, DCS-2102 versión 1.06_FR, DCS-2102 versión 1.06, DCS-2102 versión 1.05_RU, DCS-1130L versión 1.04, DCS-1130 versión 1.04_US, DCS-1130 versión 1.03, DCS-1100L versión 1.04, DCS-1100 versión 1.04_US y DCS-1100 versión 1.03, debido a credenciales embebidas que sirven como un backdoor, lo que permite a atacantes remotos acceder a la transmisión de video RTSP."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-798"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-3411_firmware:1.02:*:*:*:*:*:*:*","matchCriteriaId":"21E4F54E-78BD-4963-88C0-6B6F9D751C4B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-3411:-:*:*:*:*:*:*:*","matchCriteriaId":"5A0A639C-EC97-4CF6-B853-B9CE3EEDF399"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-3430_firmware:1.02:*:*:*:*:*:*:*","matchCriteriaId":"3595919A-23A4-42D7-BC22-9AA3E5F196E2"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-3430:-:*:*:*:*:*:*:*","matchCriteriaId":"0337488F-E15D-497E-855F-7719D4809433"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-5605_firmware:1.01:*:*:*:*:*:*:*","matchCriteriaId":"0C400977-3E3C-4010-8EFE-75F30180FF22"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-5605:-:*:*:*:*:*:*:*","matchCriteriaId":"8B92CB5D-CD8E-4768-91CE-C3497C8EA58A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-5635_firmware:1.01:*:*:*:*:*:*:*","matchCriteriaId":"76933BB0-E0C2-4F81-9B28-879EDAC49302"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-5635:-:*:*:*:*:*:*:*","matchCriteriaId":"CCFFD6C7-9379-4197-B447-1C755E6636AB"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-1100l_firmware:1.04:*:*:*:*:*:*:*","matchCriteriaId":"E0FD5F42-72DD-47F4-ABDD-E0E4D0D1754A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-1100l:-:*:*:*:*:*:*:*","matchCriteriaId":"70D1E7AB-C4EA-4B97-B788-944244777CFF"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-1130l_firmware:1.04:*:*:*:*:*:*:*","matchCriteriaId":"1B09CDBD-7DC9-4E4C-9FD6-3500C56D0B3E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-1130l:-:*:*:*:*:*:*:*","matchCriteriaId":"C6DF5842-F02E-4076-9B26-A3CC1EEBC94E"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-1100_firmware:1.03:*:*:*:*:*:*:*","matchCriteriaId":"5A26476D-57A8-481C-80CB-80CC238F083A"},{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-1100_firmware:1.04:*:*:*:*:*:*:*","matchCriteriaId":"AD48A2EC-52EB-4C4B-B1ED-EC87822EDF5C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-1100:-:*:*:*:*:*:*:*","matchCriteriaId":"704F9608-72CE-49C0-B7D2-F2FE84DF0C74"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-1130_firmware:1.03:*:*:*:*:*:*:*","matchCriteriaId":"E5A39F0C-8E3B-41AA-8E1D-E2DABB0A4CCC"},{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-1130_firmware:1.04:*:*:*:*:*:*:*","matchCriteriaId":"EA9B1618-9862-470A-AA4D-02A779B314A1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-1130:-:*:*:*:*:*:*:*","matchCriteriaId":"33A388EC-275D-4180-83E2-AD73F7EEB54F"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-2102_firmware:1.05:*:*:*:*:*:*:*","matchCriteriaId":"28CE404D-2DFF-4203-8954-FA579EF5924B"},{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-2102_firmware:1.06:*:*:*:*:*:*:*","matchCriteriaId":"309BB5E5-5664-447B-B2C0-DCE54B0FDC2F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-2102:-:*:*:*:*:*:*:*","matchCriteriaId":"78CD04CA-964A-4D74-B30E-7DC53E1858B6"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-2121_firmware:1.05:*:*:*:*:*:*:*","matchCriteriaId":"C3435DC0-44C2-440D-9C56-39EC06782BBC"},{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-2121_firmware:1.06:*:*:*:*:*:*:*","matchCriteriaId":"631443E3-859B-439D-879E-C342B514BF33"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-2121:-:*:*:*:*:*:*:*","matchCriteriaId":"FC1DE485-2705-4394-BC93-0BE99FE02F12"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-3410_firmware:1.02:*:*:*:*:*:*:*","matchCriteriaId":"1DC3F994-76E7-487C-A144-FC6C5AFDC5D9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-3410:-:*:*:*:*:*:*:*","matchCriteriaId":"4558EBD8-5FB0-487B-88E6-17E76B2B68BC"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-5230_firmware:1.02:*:*:*:*:*:*:*","matchCriteriaId":"117E4B04-541F-4398-B644-959329FF45E5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-5230:-:*:*:*:*:*:*:*","matchCriteriaId":"A17CC0BD-D224-4A30-A8CF-07E469F4BFA4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-5230l_firmware:1.02:*:*:*:*:*:*:*","matchCriteriaId":"5265C1F6-0246-4AF4-B348-86D3F8C95C0D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-5230l:-:*:*:*:*:*:*:*","matchCriteriaId":"94FFCE95-2A81-465F-B4EB-3B1BD687D87F"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-6410_firmware:1.00:*:*:*:*:*:*:*","matchCriteriaId":"2915F59C-512F-44B7-BB67-B699B622C055"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-6410:-:*:*:*:*:*:*:*","matchCriteriaId":"994CFC4C-7EC2-450A-9E05-940EE3CBA9D5"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-7410_firmware:1.00:*:*:*:*:*:*:*","matchCriteriaId":"4DDC8CC0-F1B5-4EA4-A822-50FA02476365"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-7410:-:*:*:*:*:*:*:*","matchCriteriaId":"7AC168D7-AFFD-44A9-8CB7-29E1EDF0849A"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-7510_firmware:1.00:*:*:*:*:*:*:*","matchCriteriaId":"4466E781-46D0-4A55-9136-3842E93C228A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-7510:-:*:*:*:*:*:*:*","matchCriteriaId":"EF686286-DFA4-49CE-BF64-D6BA849FDCD4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:wcs-1100_firmware:1.00:*:*:*:*:*:*:*","matchCriteriaId":"113F0277-63F1-4623-B668-88865ADFAD83"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:wcs-1100:-:*:*:*:*:*:*:*","matchCriteriaId":"D06ED3F1-B59E-447F-B4E6-D95FB834A6C1"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/59571","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/83940","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://packetstormsecurity.com/files/cve/CVE-2013-1603","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://vuldb.com/?id.8575","source":"cve@mitre.org","tags":["Permissions Required"]},{"url":"https://www.coresecurity.com/advisories/d-link-ip-cameras-multiple-vulnerabilities","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/59571","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/83940","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://packetstormsecurity.com/files/cve/CVE-2013-1603","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://vuldb.com/?id.8575","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://www.coresecurity.com/advisories/d-link-ip-cameras-multiple-vulnerabilities","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2013-2569","sourceIdentifier":"cve@mitre.org","published":"2020-01-29T18:15:11.873","lastModified":"2026-06-16T23:53:39.337","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain unauthorized access to the live video stream."},{"lang":"es","value":"Se presenta una vulnerabilidad de Omisión de Seguridad en Zavio IP Cameras versiones hasta 1.6.3, porque la autenticación del protocolo RTSP está deshabilitada por defecto, lo que podría permitir a un usuario malicioso obtener un acceso no autorizado para la transmisión de video en vivo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zavio:f3105_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.6.03","matchCriteriaId":"0EA3D3B5-239E-41C0-820C-7DEB3DD9CDFD"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zavio:f3105:-:*:*:*:*:*:*:*","matchCriteriaId":"12781300-4579-472D-A85C-E1F384CB4542"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:zavio:f312a_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.6.03","matchCriteriaId":"57095677-FBCA-4AE8-90D8-9DF1E76E2F2B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:zavio:f312a:-:*:*:*:*:*:*:*","matchCriteriaId":"A70903F5-C884-481B-A1F1-C1C304B80195"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/60191","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/84570","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://packetstormsecurity.com/files/cve/CVE-2013-2569","source":"cve@mitre.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.coresecurity.com/advisories/zavio-ip-cameras-multiple-vulnerabilities","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/60191","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/84570","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://packetstormsecurity.com/files/cve/CVE-2013-2569","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.coresecurity.com/advisories/zavio-ip-cameras-multiple-vulnerabilities","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-25747","sourceIdentifier":"cve@mitre.org","published":"2020-09-25T04:23:05.027","lastModified":"2026-06-17T03:07:13.957","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The Telnet service of Rubetek RV-3406, RV-3409, and RV-3411 cameras (firmware versions v342, v339) can allow a remote attacker to gain access to RTSP and ONFIV services without authentication. Thus, the attacker can watch live streams from the camera, rotate the camera, change some settings (brightness, clarity, time), restart the camera, or reset it to factory settings."},{"lang":"es","value":"El servicio Telnet de las cámaras RV-3406, RV-3409 y RV-3411 de Rubetek (versiones de firmware v342, v339), puede permitir a un atacante remoto conseguir acceso a los servicios RTSP y ONFIV sin autenticación.&#xa0;Por lo tanto, el atacante puede ver transmisiones en vivo desde la cámara, girar la cámara, cambiar algunas configuraciones (brillo, claridad, tiempo), reiniciar la cámara o restablecerla a la configuración de fábrica"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:C","baseScore":9.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":8.5,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:rubetek:rv-3406_firmware:339:*:*:*:*:*:*:*","matchCriteriaId":"57AF1900-5D42-45B9-9906-B1EBC933A064"},{"vulnerable":true,"criteria":"cpe:2.3:o:rubetek:rv-3406_firmware:342:*:*:*:*:*:*:*","matchCriteriaId":"72F51EDA-EA7A-4E58-A071-A0D6F3AEC379"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:rubetek:rv-3406:-:*:*:*:*:*:*:*","matchCriteriaId":"D0C29138-1CBA-4677-B494-AA5278632606"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:rubetek:rv-3409_firmware:339:*:*:*:*:*:*:*","matchCriteriaId":"B2BD4E56-46E1-4985-A46F-C9B4A374A17F"},{"vulnerable":true,"criteria":"cpe:2.3:o:rubetek:rv-3409_firmware:342:*:*:*:*:*:*:*","matchCriteriaId":"EE539B49-BF73-4411-855D-69E02E6AD917"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:rubetek:rv-3409:-:*:*:*:*:*:*:*","matchCriteriaId":"93B04FD1-8EEF-4DDC-83A9-9F5390378D28"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:rubetek:rv-3411_firmware:339:*:*:*:*:*:*:*","matchCriteriaId":"183C8C01-1F30-40F5-BD9F-6D217EB1CD42"},{"vulnerable":true,"criteria":"cpe:2.3:o:rubetek:rv-3411_firmware:342:*:*:*:*:*:*:*","matchCriteriaId":"C9ECA3AF-D4F0-4F8B-854C-0C63BB090E44"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:rubetek:rv-3411:-:*:*:*:*:*:*:*","matchCriteriaId":"0D54B518-140F-4933-A1C8-45A0A7B3F167"}]}]}],"references":[{"url":"https://github.com/jet-pentest/CVE-2020-25747","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://github.com/jet-pentest/CVE-2020-25747","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2020-24918","sourceIdentifier":"cve@mitre.org","published":"2021-04-30T12:15:07.460","lastModified":"2026-06-17T03:06:09.743","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to send a crafted RTSP request, with a long digest authentication header, to execute arbitrary code in parse_authentication_header() in libamprotocol-rtsp.so.1 in rtsp_svc (or cause a crash). This allows remote takeover of a Furbo Dog Camera, for example. NOTE: The vendor states that the RTSP library is used for DEMO only, using it in product is a customer's behavior. Ambarella has emphasized that RTSP is DEMO only library, should NOT be used in product in our document. Because Ambarella's SDK is proprietary, we didn't publish our SDK source code in public network."},{"lang":"es","value":"Un desbordamiento del búfer en el servicio RTSP del servidor Ambarella Oryx RTSP versión 07-01-2020, permite a un atacante no autenticado enviar una petición RTSP diseñada, con un encabezado de autenticación de resumen largo, para ejecutar código arbitrario en la función parse_authentication_header() en el archivo libamprotocol-rtsp.so.1 en el parámetro rtsp_svc (o causar un bloqueo).&#xa0;Esto permite la toma de control remota de una Furbo Dog Camera, por ejemplo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":10.0,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-120"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ambarella:oryx_rtsp_server:2020-01-07:*:*:*:*:*:*:*","matchCriteriaId":"EEFAFD2B-B21F-4413-ACCA-4371D73E04A1"}]}]}],"references":[{"url":"https://github.com/Ambarella-Inc/amba-cve-info/tree/main/cve-2020-24918","source":"cve@mitre.org"},{"url":"https://somersetrecon.squarespace.com/blog/2021/hacking-the-furbo-part-1","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.ambarella.com","source":"cve@mitre.org","tags":["Vendor Advisory"]},{"url":"https://www.somersetrecon.com/blog","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://somersetrecon.squarespace.com/blog/2021/hacking-the-furbo-part-1","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.ambarella.com","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.somersetrecon.com/blog","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2021-26627","sourceIdentifier":"vuln@krcert.or.kr","published":"2022-04-19T21:15:12.807","lastModified":"2026-06-17T03:43:35.433","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerability could allow to remote attackers to send the RTSP requests using ffplay command and lead to leakage a live image."},{"lang":"es","value":"Una exposición de la información de las imágenes en tiempo real está causada por una autenticación insuficiente del puerto RTSP activado. Esta vulnerabilidad podría permitir a atacantes remotos enviar las peticiones RTSP usando el comando ffplay y conllevar a un filtrado de una imagen en vivo"}],"affected":[{"source":"vuln@krcert.or.kr","affectedData":[{"vendor":"EDrhyme Co.,Ltd","product":"QCP 200W","platforms":["Windows, Android"],"versions":[{"version":"No version information","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"vuln@krcert.or.kr","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"vuln@krcert.or.kr","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:qcp:qcp200w_firmware:-:*:*:*:*:android:*:*","matchCriteriaId":"DF356B8D-9C64-4F10-861D-94CBA08B3652"},{"vulnerable":true,"criteria":"cpe:2.3:o:qcp:qcp200w_firmware:-:*:*:*:*:windows:*:*","matchCriteriaId":"652A5975-0772-4FF8-A9CD-C2D4AD4568CD"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:qcp:qcp200w:-:*:*:*:*:*:*:*","matchCriteriaId":"49EDED72-B064-40E3-AE16-279A5E1C7A81"}]}]}],"references":[{"url":"https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66663","source":"vuln@krcert.or.kr","tags":["Third Party Advisory"]},{"url":"https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66663","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-51624","sourceIdentifier":"zdi-disclosures@trendmicro.com","published":"2024-05-03T03:16:25.373","lastModified":"2026-06-17T06:41:21.013","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"D-Link DCS-8300LHV2 RTSP ValidateAuthorizationHeader Nonce Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DCS-8300LHV2 IP cameras. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the Authorization header by the RTSP server, which listens on TCP port 554. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20072."},{"lang":"es","value":"D-Link DCS-8300LHV2 RTSP ValidateAuthorizationHeader Nonce Vulnerabilidad de ejecución remota de código de desbordamiento de búfer en la región stack de la memoria. Esta vulnerabilidad permite a atacantes adyacentes a la red ejecutar código arbitrario en instalaciones afectadas de cámaras IP D-Link DCS-8300LHV2. No se requiere autenticación para aprovechar esta vulnerabilidad. La falla específica existe en el manejo del encabezado de Autorización por parte del servidor RTSP, que escucha en el puerto TCP 554. El problema se debe a la falta de una validación adecuada de la longitud de los datos proporcionados por el usuario antes de copiarlos en un búfer basado en pila de longitud fija. Un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto de la raíz. Fue ZDI-CAN-20072."}],"affected":[{"source":"zdi-disclosures@trendmicro.com","affectedData":[{"vendor":"D-Link","product":"DCS-8300LHV2","defaultStatus":"unknown","versions":[{"version":"1.06.01","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"d-link","product":"DCS-8300LHV2","defaultStatus":"unknown","cpes":["cpe:2.3:a:d-link:DCS-8300LHV2:1.06.01:*:*:*:*:*:*:*"],"versions":[{"version":"1.06.01","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV30":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-03T18:14:43.187628Z","id":"CVE-2023-51624","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-8300lhv2_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.07.02","matchCriteriaId":"B5E6108B-5223-48D0-ACD3-56A21F091F6C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-8300lhv2:-:*:*:*:*:*:*:*","matchCriteriaId":"370C3425-5B83-4E93-9C84-FA625EFB93EC"}]}]}],"references":[{"url":"https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10370","source":"zdi-disclosures@trendmicro.com","tags":["Vendor Advisory"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-24-044/","source":"zdi-disclosures@trendmicro.com","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10370","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-24-044/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-51626","sourceIdentifier":"zdi-disclosures@trendmicro.com","published":"2024-05-03T03:16:25.713","lastModified":"2026-06-17T06:41:21.260","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"D-Link DCS-8300LHV2 RTSP ValidateAuthorizationHeader Username Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DCS-8300LHV2 IP cameras. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the Authorization header by the RTSP server, which listens on TCP port 554. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21320."},{"lang":"es","value":"D-Link DCS-8300LHV2 RTSP ValidateAuthorizationHeader Username Vulnerabilidad de ejecución remota de código de desbordamiento de búfer en la región stack de la memoria. Esta vulnerabilidad permite a atacantes adyacentes a la red ejecutar código arbitrario en instalaciones afectadas de cámaras IP D-Link DCS-8300LHV2. No se requiere autenticación para aprovechar esta vulnerabilidad. La falla específica existe en el manejo del encabezado de Autorización por parte del servidor RTSP, que escucha en el puerto TCP 554. El problema se debe a la falta de una validación adecuada de la longitud de los datos proporcionados por el usuario antes de copiarlos en un búfer basado en pila de longitud fija. Un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto de la raíz. Era ZDI-CAN-21320."}],"affected":[{"source":"zdi-disclosures@trendmicro.com","affectedData":[{"vendor":"D-Link","product":"DCS-8300LHV2","defaultStatus":"unknown","versions":[{"version":"1.06.01","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"dlink","product":"dcs-8300lvh2_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:dlink:dcs-8300lvh2_firmware:1.06.01:*:*:*:*:*:*:*"],"versions":[{"version":"1.06.01","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV30":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-06T17:54:28.518664Z","id":"CVE-2023-51626","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dlink:dcs-8300lhv2_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.07.02","matchCriteriaId":"B5E6108B-5223-48D0-ACD3-56A21F091F6C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:dlink:dcs-8300lhv2:-:*:*:*:*:*:*:*","matchCriteriaId":"370C3425-5B83-4E93-9C84-FA625EFB93EC"}]}]}],"references":[{"url":"https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10370","source":"zdi-disclosures@trendmicro.com","tags":["Vendor Advisory"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-24-046/","source":"zdi-disclosures@trendmicro.com","tags":["Third Party Advisory"]},{"url":"https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10370","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-24-046/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2024-39350","sourceIdentifier":"security@synology.com","published":"2024-06-28T07:15:06.330","lastModified":"2026-06-17T07:41:46.400","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.7-0298 may be affected: BC500 and TC500."},{"lang":"es","value":"Se encuentra una vulnerabilidad relacionada con la omisión de autenticación mediante suplantación de identidad en la funcionalidad RTSP. Esto permite a los atacantes intermediarios obtener privilegios sin consentimiento a través de vectores no especificados. Los siguientes modelos con versiones de firmware de cámara Synology anteriores a 1.0.7-0298 pueden verse afectados: BC500 y TC500."}],"affected":[{"source":"security@synology.com","affectedData":[{"vendor":"Synology","product":"Camera Firmware","defaultStatus":"affected","platforms":["BC500","TC500"],"versions":[{"version":"1.0","lessThan":"1.0.7-0298","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"synology","product":"camera_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:a:synology:camera_firmware:*:*:*:*:*:*:*:*"],"versions":[{"version":"1.0","lessThan":"1.0.7-0298","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@synology.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-06-28T14:02:43.291362Z","id":"CVE-2024-39350","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@synology.com","type":"Secondary","description":[{"lang":"en","value":"CWE-290"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:synology:tc500_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.0.7-0298","matchCriteriaId":"F4DBB838-E652-4C96-AC50-AF07510EF8E5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:synology:tc500:-:*:*:*:*:*:*:*","matchCriteriaId":"582C2C89-3351-4DC6-B40A-7E2E4CA6AFEA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:synology:bc500_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.0.7-0298","matchCriteriaId":"11106950-DFD0-441A-8DE3-DA19C15281B1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:synology:bc500:-:*:*:*:*:*:*:*","matchCriteriaId":"5FD618BD-29BD-4F43-9BEF-F73065247580"}]}]}],"references":[{"url":"https://www.synology.com/en-global/security/advisory/Synology_SA_23_15","source":"security@synology.com","tags":["Vendor Advisory"]},{"url":"https://www.synology.com/en-global/security/advisory/Synology_SA_23_15","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2024-51362","sourceIdentifier":"cve@mitre.org","published":"2024-11-05T17:15:07.383","lastModified":"2026-06-17T08:05:38.113","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising user privacy and security. No credentials or special permissions are required, and access can be gained remotely over the network."},{"lang":"es","value":"LSC Smart Connect Indoor IP Camera V7.6.32 es vulnerable a un problema de divulgación de información que permite acceder a las imágenes en vivo de la cámara a través del protocolo RTSP en el puerto 8554 sin necesidad de autenticación. Esto permite que usuarios no autorizados con acceso a la red vean la señal de la cámara, lo que podría comprometer la privacidad y la seguridad del usuario. No se requieren credenciales ni permisos especiales, y se puede acceder de forma remota a través de la red."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"lsc_smart_connect","product":"indoor_camera_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:lsc_smart_connect:indoor_camera_firmware:7.6.32:*:*:*:*:*:*:*"],"versions":[{"version":"7.6.32","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-06T19:24:40.444092Z","id":"CVE-2024-51362","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://shinxyy.github.io/blogs/CVE_2024_51362.html","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2025-6528","sourceIdentifier":"cna@vuldb.com","published":"2025-06-23T23:15:23.783","lastModified":"2026-06-17T10:02:05.063","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability has been found in 70mai M300 up to 20250611 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /livestream/12 of the component RTSP Live Video Stream Endpoint. The manipulation leads to improper authentication. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."},{"lang":"es","value":"Se ha detectado una vulnerabilidad en 70mai M300 hasta el 20250611, clasificada como problemática. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo /livestream/12 del componente RTSP Live Video Stream Endpoint. La manipulación provoca una autenticación incorrecta. El ataque debe realizarse dentro de la red local. Se ha hecho público el exploit y puede que sea utilizado. Se contactó al proveedor con antelación para informarle sobre esta divulgación, pero no respondió."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"70mai","product":"M300","modules":["RTSP Live Video Stream Endpoint"],"versions":[{"version":"20250611","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:L/Au:N/C:P/I:N/A:N","baseScore":3.3,"accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.5,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-24T16:33:36.468429Z","id":"CVE-2025-6528","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:70mai:m300_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"2025-06-11","matchCriteriaId":"74F76A59-3C12-4CFD-9EBC-81A9E118FB06"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:70mai:m300:-:*:*:*:*:*:*:*","matchCriteriaId":"22FFE3AD-B83F-4987-896C-11A6E936F2C8"}]}]}],"references":[{"url":"https://github.com/geo-chen/70mai/blob/main/README.md#finding-6-unauthenticated-live-video-stream","source":"cna@vuldb.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://vuldb.com/?ctiid.313645","source":"cna@vuldb.com","tags":["Permissions Required","VDB Entry"]},{"url":"https://vuldb.com/?id.313645","source":"cna@vuldb.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://vuldb.com/?submit.595449","source":"cna@vuldb.com","tags":["Third Party Advisory","VDB Entry"]}]}},{"cve":{"id":"CVE-2025-30135","sourceIdentifier":"cve@mitre.org","published":"2025-07-25T20:15:24.203","lastModified":"2026-06-17T09:08:13.540","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication controls on its HTTP and RTSP interfaces, allowing attackers to retrieve sensitive files and video recordings. By connecting to http://192.168.10.1/mnt/extsd/event/, an attacker can download all stored video recordings in an unencrypted manner. Additionally, the RTSP stream on port 8554 is accessible without authentication, allowing an attacker to view live footage."},{"lang":"es","value":"Se detectó un problema en los dispositivos IROAD Dashcam FX2. Es posible que se descarguen archivos mediante HTTP y RTSP sin autenticación. Carecen de controles de autenticación en sus interfaces HTTP y RTSP, lo que permite a los atacantes recuperar archivos y grabaciones de vídeo confidenciales. Al conectarse a http://192.168.10.1/mnt/extsd/event/, un atacante puede descargar todas las grabaciones de vídeo almacenadas sin cifrar. Además, se puede acceder a la transmisión RTSP en el puerto 8554 sin autenticación, lo que permite a un atacante ver grabaciones en directo."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-25T19:39:52.997964Z","id":"CVE-2025-30135","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:iroadau:fx2_firmware:-:*:*:*:*:*:*:*","matchCriteriaId":"A1C21728-4D54-42DB-98C8-B0B7C7A38B2C"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:iroadau:fx2:-:*:*:*:*:*:*:*","matchCriteriaId":"8E62E438-2D69-401D-B5A8-B54565CE049E"}]}]}],"references":[{"url":"https://github.com/geo-chen/IROAD?tab=readme-ov-file#finding-13---cve-2025-30135-locking-owner-out-of-device-dos","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://github.com/geo-chen/IROAD?tab=readme-ov-file#finding-8-dumping-files-over-http-and-rtsp-without-authentication","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.iroadau.com.au/downloads/","source":"cve@mitre.org","tags":["Product"]}]}},{"cve":{"id":"CVE-2025-56578","sourceIdentifier":"cve@mitre.org","published":"2025-09-10T15:15:37.290","lastModified":"2026-06-17T09:42:41.420","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in RTSPtoWeb v.2.4.3 allows a remote attacker to obtain sensitive information and executearbitrary code via the lack of authentication mechanisms"},{"lang":"es","value":"Un problema en RTSPtoWeb v.2.4.3 permite a un atacante remoto obtener información sensible y ejecutar código arbitrario debido a la falta de mecanismos de autenticación."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-10-15T16:17:44.060827Z","id":"CVE-2025-56578","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://github.com/God-mellon/article/blob/main/RTSPtoWeb-Unauthorized%20Access%20Vulnerability.pdf","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2025-14746","sourceIdentifier":"cna@vuldb.com","published":"2025-12-16T03:15:57.233","lastModified":"2026-06-17T08:36:29.817","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability has been found in Ningyuanda TC155 57.0.2.0. The affected element is an unknown function of the component RTSP Live Video Stream Endpoint. Such manipulation leads to improper authentication. The attack must be carried out from within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"Ningyuanda","product":"TC155","modules":["RTSP Live Video Stream Endpoint"],"versions":[{"version":"57.0.2.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:L/Au:N/C:P/I:N/A:N","baseScore":3.3,"accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.5,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-16T21:22:50.884264Z","id":"CVE-2025-14746","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:shenzhenningyuandatechnology:tc155_firmware:57.0.2.0:*:*:*:*:*:*:*","matchCriteriaId":"BC8CEF63-8B37-4D17-8C31-4BD41E7B8D5B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:shenzhenningyuandatechnology:tc155:-:*:*:*:*:*:*:*","matchCriteriaId":"0DC27CA3-9706-448B-8C91-E413B1F05656"}]}]}],"references":[{"url":"https://github.com/pwnpwnpur1n/IoT-advisories/blob/main/TC155-Unauth-RTSP.md","source":"cna@vuldb.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://vuldb.com/?ctiid.336519","source":"cna@vuldb.com","tags":["Permissions Required","VDB Entry"]},{"url":"https://vuldb.com/?id.336519","source":"cna@vuldb.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://vuldb.com/?submit.707195","source":"cna@vuldb.com","tags":["Third Party Advisory","VDB Entry"]}]}},{"cve":{"id":"CVE-2018-25141","sourceIdentifier":"disclosure@vulncheck.com","published":"2025-12-24T20:15:48.270","lastModified":"2026-06-17T01:54:48.440","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"FLIR thermal traffic cameras contain an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve video streams by accessing specific endpoints like /live.mjpeg, /snapshot.jpg, and RTSP streaming URLs without authentication."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"FLIR","product":"FLIR Thermal Traffic Cameras","versions":[{"version":"1.01-0bb5b27","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-24T20:12:24.430897Z","id":"CVE-2018-25141","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://www.exploit-db.com/exploits/45537","source":"disclosure@vulncheck.com"},{"url":"https://www.flir.com","source":"disclosure@vulncheck.com"},{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5489.php","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/45537","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5489.php","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2019-25248","sourceIdentifier":"disclosure@vulncheck.com","published":"2025-12-24T20:15:53.093","lastModified":"2026-06-17T02:31:52.563","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Beward N100 M2.1.6.04C014 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly retrieve the camera's RTSP stream by exploiting the lack of authentication in the video access mechanism."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Beward","product":"N100 H.264 VGA IP Camera","versions":[{"version":"M2.1.6.04C014","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-12-24T20:02:37.080531Z","id":"CVE-2019-25248","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://www.beward.net","source":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/46317","source":"disclosure@vulncheck.com"},{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5509.php","source":"disclosure@vulncheck.com"},{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5509.php","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2025-66049","sourceIdentifier":"cvd@cert.pl","published":"2026-01-09T12:15:53.420","lastModified":"2026-06-17T09:56:14.510","vulnStatus":"Analyzed","cveTags":[{"sourceIdentifier":"cvd@cert.pl","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising user privacy and security. \nThe vendor has not replied to the CNA. Possibly all firmware versions are affected. Since the product has met End-Of-Life phase, a fix is not expected to be released."},{"lang":"es","value":"La cámara Vivotek IP7137 con la versión de firmware 0200a es vulnerable a un problema de revelación de información donde las imágenes de la cámara en vivo pueden ser accedidas a través del protocolo RTSP en el puerto 8554 sin requerir autenticación. Esto permite a usuarios no autorizados con acceso a la red ver la transmisión de la cámara, comprometiendo potencialmente la privacidad y seguridad del usuario.\nEl proveedor no ha respondido a la CNA. Posiblemente todas las versiones de firmware estén afectadas. Dado que el producto ha alcanzado la fase de Fin de Vida Útil, no se espera que se lance una solución."}],"affected":[{"source":"cvd@cert.pl","affectedData":[{"vendor":"Vivotek","product":"IP7137","defaultStatus":"unknown","versions":[{"version":"0200a","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cvd@cert.pl","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-09T16:22:03.331793Z","id":"CVE-2025-66049","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cvd@cert.pl","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:vivotek:ip7137_firmware:0200a:*:*:*:*:*:*:*","matchCriteriaId":"7FBD8C69-D2F8-46B0-AE09-F6296BD22414"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:vivotek:ip7137:-:*:*:*:*:*:*:*","matchCriteriaId":"2BE1F29C-4CF4-46B7-862B-C4B3F00B70EE"}]}]}],"references":[{"url":"https://cert.pl/posts/2026/01/CVE-2025-66049","source":"cvd@cert.pl","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-26340","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-02-24T20:27:47.793","lastModified":"2026-06-17T10:26:07.577","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requiring authentication. A remote attacker can connect to the RTSP service and access live video/audio streams without valid credentials, resulting in unauthorized disclosure of surveillance data."},{"lang":"es","value":"Las versiones de firmware 1.181.5 y anteriores de las familias de dispositivos Tattile Smart+, Vega y Basic exponen flujos RTSP sin requerir autenticación. Un atacante remoto puede conectarse al servicio RTSP y acceder a flujos de video/audio en vivo sin credenciales válidas, lo que resulta en la divulgación no autorizada de datos de vigilancia."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Tattile s.r.l.","product":"Smart+","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.181.5","versionType":"semver","status":"affected"}]},{"vendor":"Tattile s.r.l.","product":"Tolling+","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.181.5","versionType":"semver","status":"affected"}]},{"vendor":"Tattile s.r.l.","product":"Smart+ Speed","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.181.5","versionType":"semver","status":"affected"}]},{"vendor":"Tattile s.r.l.","product":"Smart+ Traffic Light","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.181.5","versionType":"semver","status":"affected"}]},{"vendor":"Tattile s.r.l.","product":"Axle Counter","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.181.5","versionType":"semver","status":"affected"}]},{"vendor":"Tattile s.r.l.","product":"Vega53","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.181.5","versionType":"semver","status":"affected"}]},{"vendor":"Tattile s.r.l.","product":"Vega33","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.181.5","versionType":"semver","status":"affected"}]},{"vendor":"Tattile s.r.l.","product":"Vega11","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.181.5","versionType":"semver","status":"affected"}]},{"vendor":"Tattile s.r.l.","product":"Basic MK2","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.181.5","versionType":"semver","status":"affected"}]},{"vendor":"Tattile s.r.l.","product":"ANPR Mobile","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.181.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-02-24T21:33:55.002164Z","id":"CVE-2026-26340","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tattile:smart\\+_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.181.5","matchCriteriaId":"75DF648A-23A7-4CD7-A7AA-EC4E5041C11A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tattile:smart\\+:-:*:*:*:*:*:*:*","matchCriteriaId":"B19D09F0-9D90-4D42-8866-351C464B45BC"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tattile:tolling\\+_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.181.5","matchCriteriaId":"7CC79296-730F-40BF-A4CC-CB711452BFCF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tattile:tolling\\+:-:*:*:*:*:*:*:*","matchCriteriaId":"7085AB6F-B3A7-48B3-996A-DF842B2D7217"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tattile:smart\\+_speed_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.181.5","matchCriteriaId":"6FCA661E-7976-4F6A-A79E-FFC3355C4A90"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tattile:smart\\+_speed:-:*:*:*:*:*:*:*","matchCriteriaId":"F3DE404C-063D-4775-9C8B-972D5C34B128"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tattile:smart\\+_traffic_light_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.181.5","matchCriteriaId":"83B0F41B-E7F4-4D72-B041-A27AC19EF8BA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tattile:smart\\+_traffic_light:-:*:*:*:*:*:*:*","matchCriteriaId":"9648971C-A3ED-4E3C-AC58-EC8E24C1BACD"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tattile:axle_counter_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.181.5","matchCriteriaId":"A0360803-0FF4-46FB-913D-FD0724C74139"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tattile:axle_counter:-:*:*:*:*:*:*:*","matchCriteriaId":"48535F53-6935-4F1B-B0CA-71721D82B344"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tattile:vega53_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.181.5","matchCriteriaId":"09CF177A-3D69-4F47-8028-F83493CF0178"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tattile:vega53:-:*:*:*:*:*:*:*","matchCriteriaId":"DA18F44D-09EC-462A-AEE1-2734F74D9214"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tattile:vega33_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.181.5","matchCriteriaId":"FC4C241F-FF66-480B-8708-FDC1814DE167"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tattile:vega33:-:*:*:*:*:*:*:*","matchCriteriaId":"88626B12-E13C-4606-81E1-998C74CD6485"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tattile:vega11_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.181.5","matchCriteriaId":"026FF8B9-AEA6-45FF-8FA9-BE97C20A66E1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tattile:vega11:-:*:*:*:*:*:*:*","matchCriteriaId":"918205FF-3BC6-4A38-980A-CE0BF36EE9EF"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tattile:basic_mk2_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.181.5","matchCriteriaId":"72B5F07C-949A-440F-AB94-46C5AF5F46C3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tattile:basic_mk2:-:*:*:*:*:*:*:*","matchCriteriaId":"A59DD6EA-AE66-4AF6-A2F0-5A84F2F809BB"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tattile:anpr_mobile_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.181.5","matchCriteriaId":"FF40F60E-1D89-4A51-B1AC-0BE34878AD1E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tattile:anpr_mobile:-:*:*:*:*:*:*:*","matchCriteriaId":"7456A228-07C2-4E9A-98A9-8485F993C281"}]}]}],"references":[{"url":"https://www.tattile.com/","source":"disclosure@vulncheck.com","tags":["Product"]},{"url":"https://www.vulncheck.com/advisories/tattile-smart-vega-basic-unauthenticated-rtsp-stream-disclosure","source":"disclosure@vulncheck.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5978.php","source":"disclosure@vulncheck.com","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-35902","sourceIdentifier":"cve@mitre.org","published":"2026-04-27T19:16:51.060","lastModified":"2026-06-17T10:41:01.953","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication parameters, an unauthenticated attacker can cause the RTSP service to enter a persistent authentication failure state, preventing legitimate clients from authenticating and leading to a denial of service."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":6.2,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.5,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-28T12:52:33.239510Z","id":"CVE-2026-35902","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-307"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:mercurycom:mipc252w_firmware:1.0.5:build_230306:*:*:*:*:*:*","matchCriteriaId":"61FE2E9E-C0F5-4F45-B4F4-10E05CEB0395"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:mercurycom:mipc252w:-:*:*:*:*:*:*:*","matchCriteriaId":"5CBF3BC0-1845-4D38-BFD2-3B02219C1BD8"}]}]}],"references":[{"url":"https://github.com/izxnfirh8148/CVE_REQUESTS_references/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_3th/README.md","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/izxnfirh8148/CVE_REQUESTS_references/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_3th/README.md","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-35903","sourceIdentifier":"cve@mitre.org","published":"2026-04-27T19:16:52.817","lastModified":"2026-06-17T10:41:02.117","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, the device does not verify the Digest response parameter in subsequent RTSP requests within the same session. As a result, RTSP methods such as SETUP, PLAY, and TEARDOWN can be processed even when the Authorization header contains an empty or invalid response value, as long as the nonce and session identifier correspond to a previously authenticated session. This allows an attacker with network access to reuse session parameters and issue unauthorized RTSP control commands without computing a valid Digest response."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-04-28T14:55:03.765688Z","id":"CVE-2026-35903","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:mercurycom:mipc252w_firmware:1.0.5:build_230306:*:*:*:*:*:*","matchCriteriaId":"61FE2E9E-C0F5-4F45-B4F4-10E05CEB0395"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:mercurycom:mipc252w:-:*:*:*:*:*:*:*","matchCriteriaId":"5CBF3BC0-1845-4D38-BFD2-3B02219C1BD8"}]}]}],"references":[{"url":"https://github.com/izxnfirh8148/CVE_REQUESTS_references/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_4th/README.md","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/izxnfirh8148/CVE_REQUESTS_references/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_4th/README.md","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2026-41470","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-05-19T19:16:50.440","lastModified":"2026-07-24T09:10:00.153","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions."},{"lang":"es","value":"LIVE555 anterior a 2026.04.22 contiene una vulnerabilidad de omisión de autorización en el manejo de comandos de sesión RTSP que permite a los atacantes reproducir tokens de sesión válidos desde conexiones no autenticadas. Los atacantes que obtienen un token de sesión válido pueden emitir comandos PLAY y TEARDOWN desde una segunda conexión TCP sin autenticación, causando caídas del servidor a través de errores de llamada a funciones virtuales o interrumpiendo transmisiones activas al terminar sesiones de víctimas."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Live Networks, Inc.","product":"LIVE555","defaultStatus":"affected","versions":[{"version":"0","lessThan":"2026.04.22","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-20T14:03:45.166155Z","id":"CVE-2026-41470","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://download.live555.com/","source":"disclosure@vulncheck.com"},{"url":"https://gist.github.com/yhcho0405/ee9b67a96808ef19f22e8a4ee88c795f","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/live555-rtsp-server-authorization-bypass-via-session-token","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-1871","sourceIdentifier":"f23511db-6c3e-4e32-a477-6aa17d310630","published":"2026-06-02T17:16:26.967","lastModified":"2026-07-22T19:10:00.120","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request.\n\nSuccessful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition.  This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts."},{"lang":"es","value":"TP-Link Tapo C200 v5 contiene una falla de desbordamiento de búfer basado en pila en el manejo de la autenticación RTSP debido a la validación incorrecta de las longitudes de los campos del encabezado de autorización, que puede ser activada por una solicitud de autenticación manipulada.\n\nLa explotación exitosa provoca que el proceso del servicio central RTSP afectado se bloquee y desencadena un reinicio automático del sistema, lo que resulta en una condición de denegación de servicio (DoS). Esto impide que los usuarios legítimos accedan a la transmisión de video en vivo de la cámara o la interfaz de administración hasta que el servicio se reinicie."}],"affected":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","affectedData":[{"vendor":"TP-Link Systems Inc.","product":"Tapo C200 v5","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.4.4 Build 260527 Rel.28339n","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-02T18:21:22.840412Z","id":"CVE-2026-1871","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"f23511db-6c3e-4e32-a477-6aa17d310630","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:tapo_c200_firmware:1.0.5:build_240327:*:*:*:*:*:*","matchCriteriaId":"05C15E7C-DAED-4332-B38E-492608EA97CD"},{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:tapo_c200_firmware:1.0.12:build_240527:*:*:*:*:*:*","matchCriteriaId":"729217F5-CB01-4B88-BDC0-4765DF737758"},{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:tapo_c200_firmware:1.0.13:build_240619:*:*:*:*:*:*","matchCriteriaId":"544121C2-D1BA-4FF5-9DA8-26CD67119774"},{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:tapo_c200_firmware:1.0.17:build_240806:*:*:*:*:*:*","matchCriteriaId":"950B6D8F-158C-4DC6-BDC0-6923B0836DAF"},{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:tapo_c200_firmware:1.1.4:build_241219:*:*:*:*:*:*","matchCriteriaId":"0AA70F8C-56CA-4A9E-8BFE-4B8BE5127015"},{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:tapo_c200_firmware:1.1.8:build_250310:*:*:*:*:*:*","matchCriteriaId":"800DB4F6-511D-489F-A500-CF1575A86539"},{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:tapo_c200_firmware:1.2.3:build_250610:*:*:*:*:*:*","matchCriteriaId":"40E223AB-51B4-4843-A82F-32145A89CFFA"},{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.1:build_250910:*:*:*:*:*:*","matchCriteriaId":"98638E32-86B0-451C-96CA-E39C092CEB49"},{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.3:build_251119:*:*:*:*:*:*","matchCriteriaId":"C7BC3B8D-0AAB-472A-9DC3-1FCACD246183"},{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.5:build_260228:*:*:*:*:*:*","matchCriteriaId":"340E2167-A8D1-4B17-904F-895574C9A3FF"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:tapo_c200:5:*:*:*:*:*:*:*","matchCriteriaId":"DF4B31A6-FDFD-41C5-9BEF-114B290CCBAE"}]}]}],"references":[{"url":"https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Release Notes"]},{"url":"https://www.tp-link.com/kr/support/download/tapo-c200/#Firmware-Release-Notes","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Release Notes"]},{"url":"https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Release Notes"]},{"url":"https://www.tp-link.com/us/support/faq/5113/","source":"f23511db-6c3e-4e32-a477-6aa17d310630","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-57879","sourceIdentifier":"0df08a0e-a200-4957-9bb0-084f562506f9","published":"2026-06-26T08:16:24.877","lastModified":"2026-06-26T17:16:35.653","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"An unauthenticated\nstack-based buffer overflow vulnerability exists in ssvr in GeoVision\nGV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by\ninsufficient bounds checking when processing RTSP custom authentication data. A\nremote attacker may exploit this vulnerability by sending a crafted RTSP\nrequest, resulting in memory corruption, denial of service, or potentially\narbitrary code execution."}],"affected":[{"source":"0df08a0e-a200-4957-9bb0-084f562506f9","affectedData":[{"vendor":"GeoVision Inc.","product":"GV-LPCLPC2011/2211","defaultStatus":"unaffected","platforms":["Linux"],"versions":[{"version":"1.12","status":"affected"},{"version":"1.13","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"0df08a0e-a200-4957-9bb0-084f562506f9","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-26T15:55:55.481404Z","id":"CVE-2026-57879","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"0df08a0e-a200-4957-9bb0-084f562506f9","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://www.geovision.com.tw/cyber_security.php","source":"0df08a0e-a200-4957-9bb0-084f562506f9"}]}},{"cve":{"id":"CVE-2026-57880","sourceIdentifier":"0df08a0e-a200-4957-9bb0-084f562506f9","published":"2026-06-26T08:16:24.983","lastModified":"2026-06-26T18:17:04.987","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"An unauthenticated\nstack-based buffer overflow vulnerability exists in ssvr in GeoVision\nGV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by\ninsufficient bounds checking when parsing RTSP Digest authentication fields. A\nremote attacker may exploit this vulnerability by sending a crafted RTSP\nrequest containing overly long authentication data, resulting in memory\ncorruption, denial of service, or potentially arbitrary code execution."}],"affected":[{"source":"0df08a0e-a200-4957-9bb0-084f562506f9","affectedData":[{"vendor":"GeoVision Inc.","product":"GV-LPCLPC2011/2211","defaultStatus":"unaffected","platforms":["Linux"],"versions":[{"version":"1.12","status":"affected"},{"version":"1.13","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"0df08a0e-a200-4957-9bb0-084f562506f9","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-26T17:10:51.871244Z","id":"CVE-2026-57880","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"0df08a0e-a200-4957-9bb0-084f562506f9","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://www.geovision.com.tw/cyber_security.php","source":"0df08a0e-a200-4957-9bb0-084f562506f9"}]}},{"cve":{"id":"CVE-2026-51597","sourceIdentifier":"cve@mitre.org","published":"2026-07-09T17:16:59.333","lastModified":"2026-07-10T18:51:16.090","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video stream."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-10T17:26:33.701049Z","id":"CVE-2026-51597","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-294"}]}],"references":[{"url":"https://github.com/kkkk2222874/cve_ID_report/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_5th/README.md","source":"cve@mitre.org"},{"url":"https://github.com/kkkk2222874/cve_ID_report/blob/main/MERCURY_MIPC252W/MERCURY_MIPC252W_5th/README.md","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2025-70962","sourceIdentifier":"cve@mitre.org","published":"2026-08-05T14:16:58.390","lastModified":"2026-08-05T20:17:04.247","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication mechanism. An attacker with network access can use the unchangeable default credentials to access the RTSP video stream, resulting in unauthorized viewing of camera footage."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-05T19:29:08.754396Z","id":"CVE-2025-70962","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://github.com/namaek2/CVE-2025-70962","source":"cve@mitre.org"},{"url":"https://www.zositech.com/","source":"cve@mitre.org"},{"url":"https://github.com/namaek2/CVE-2025-70962","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-19749","sourceIdentifier":"cna@vuldb.com","published":"2026-08-13T21:17:46.557","lastModified":"2026-08-18T02:17:25.340","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is now public and may be used."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"Tenda","product":"CH7","cpes":["cpe:2.3:h:tenda:ch7:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"versions":[{"version":"20260625","status":"affected"}]},{"vendor":"Tenda","product":"CH7G","cpes":["cpe:2.3:h:tenda:ch7g:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"versions":[{"version":"20260625","status":"affected"}]},{"vendor":"Tenda","product":"CH10","cpes":["cpe:2.3:h:tenda:ch10:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"versions":[{"version":"20260625","status":"affected"}]},{"vendor":"Tenda","product":"CP3","cpes":["cpe:2.3:h:tenda:cp3:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"versions":[{"version":"20260625","status":"affected"}]},{"vendor":"Tenda","product":"CP3 Pro","cpes":["cpe:2.3:h:tenda:cp3_pro:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"versions":[{"version":"20260625","status":"affected"}]},{"vendor":"Tenda","product":"CP7","cpes":["cpe:2.3:h:tenda:cp7:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"versions":[{"version":"20260625","status":"affected"}]},{"vendor":"Tenda","product":"TC3B14C","cpes":["cpe:2.3:h:tenda:tc3b14c:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"versions":[{"version":"20260625","status":"affected"}]},{"vendor":"Tenda","product":"TC3B15C","cpes":["cpe:2.3:h:tenda:tc3b15c:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"versions":[{"version":"20260625","status":"affected"}]},{"vendor":"Tenda","product":"TC3T14C","cpes":["cpe:2.3:h:tenda:tc3t14c:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"versions":[{"version":"20260625","status":"affected"}]},{"vendor":"Tenda","product":"TC3T15C","cpes":["cpe:2.3:h:tenda:tc3t15c:*:*:*:*:*:*:*:*"],"modules":["RTSP/ONVIF"],"versions":[{"version":"20260625","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.9,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-18T01:37:31.729628Z","id":"CVE-2026-19749","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"},{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/howitouchyou/Tenda-Smart-Camera-Vulnerability/blob/main/Tenda%20RTSP_ONVIF%20Auth%20Bypass/Tenda%20RTSP_ONVIF%20Auth%20Bypass.md","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-19749","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/868503","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/389500","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/389500/cti","source":"cna@vuldb.com"},{"url":"https://www.tenda.com.cn/","source":"cna@vuldb.com"},{"url":"https://github.com/howitouchyou/Tenda-Smart-Camera-Vulnerability/blob/main/Tenda%20RTSP_ONVIF%20Auth%20Bypass/Tenda%20RTSP_ONVIF%20Auth%20Bypass.md","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-18279","sourceIdentifier":"zdi-disclosures@trendmicro.com","published":"2026-08-20T17:17:24.280","lastModified":"2026-08-31T20:18:58.677","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the handling of SETUP RTSP packets. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-29042."}],"affected":[{"source":"zdi-disclosures@trendmicro.com","affectedData":[{"vendor":"Sony","product":"XAV-9500ES","defaultStatus":"unknown","versions":[{"version":"3.02.00","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-21T19:55:25.085703Z","id":"CVE-2026-18279","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"zdi-disclosures@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-120"}]}],"references":[{"url":"https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-9500es/software/00274922","source":"zdi-disclosures@trendmicro.com"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-472/","source":"zdi-disclosures@trendmicro.com"}]}},{"cve":{"id":"CVE-2026-56718","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-08-30T21:16:34.160","lastModified":"2026-09-04T15:17:34.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI. Attackers can send crafted HTTP requests to port 80 without authentication to access sensitive files including cleartext RTSP credentials, Wi-Fi SSID and pre-shared key, device serial number, and cloud binding parameters."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"AJCloud","product":"AJY IPC Firmware","defaultStatus":"affected","versions":[{"version":"0","lessThan":"01.10715.11.37","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-01T14:14:31.475123Z","id":"CVE-2026-56718","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://hellkid.dev/writeups/cve-2026-56718/","source":"disclosure@vulncheck.com"},{"url":"https://www.ajcloud.net/","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ajcloud-ajy-ipc-firmware-path-traversal-via-jdbhttpd","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85150","sourceIdentifier":"secalert@redhat.com","published":"2026-09-03T13:06:21.910","lastModified":"2026-09-03T18:12:56.407","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-base","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-base","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-base","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-base","cpes":["cpe:/o:redhat:enterprise_linux:9"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-03T12:33:40.281754Z","id":"CVE-2026-85150","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Primary","description":[{"lang":"en","value":"CWE-476"}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-85150","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527936","source":"secalert@redhat.com"},{"url":"https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/120","source":"secalert@redhat.com"},{"url":"https://gitlab.freedesktop.org/gstreamer/gstreamer/-/blob/main/subprojects/gst-plugins-base/gst-libs/gst/rtsp/gstrtspmessage.c#L1408","source":"secalert@redhat.com"}]}}]}