Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Beward N100 H.264 VGA IP Camera M2.1.6 Authenticated File Disclosure
Vulnerability Description
Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to read arbitrary system files via the 'READ.filePath' parameter. Attackers can exploit the fileread script or SendCGICMD API to access sensitive files like /etc/passwd and /etc/issue by supplying absolute file paths.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Beward N100 安全漏洞
Vulnerability Description
Beward N100是俄罗斯Beward开源的一款IP视频编解码器。 Beward N100 H.264 VGA IP Camera M2.1.6版本存在安全漏洞,该漏洞源于对READ.filePath参数验证不足,可能导致任意文件泄露。
CVSS Information
N/A
Vulnerability Type
N/A