Vulnerability Description
download.rsp on ShenZhen Anni "5 in 1 XVR" devices allows remote attackers to download the configuration (without a login) to discover the password.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Annigroup | 5 In 1 Xvr Firmware | - |
| Annigroup | 5 In 1 Xvr | - |
Related Weaknesses (CWE)
References
- https://github.com/D0neMkj/EXP_IOT/blob/master/CAMERA/XVR_camera/readmeThird Party Advisory
- https://github.com/D0neMkj/EXP_IOT/tree/master/CAMERA/XVR_cameraExploitThird Party Advisory
- https://github.com/D0neMkj/EXP_IOT/blob/master/CAMERA/XVR_camera/readmeThird Party Advisory
- https://github.com/D0neMkj/EXP_IOT/tree/master/CAMERA/XVR_cameraExploitThird Party Advisory
FAQ
What is CVE-2018-10770?
CVE-2018-10770 is a vulnerability with a CVSS score of 9.8 (CRITICAL). download.rsp on ShenZhen Anni "5 in 1 XVR" devices allows remote attackers to download the configuration (without a login) to discover the password.
How severe is CVE-2018-10770?
CVE-2018-10770 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-10770?
Check the references section above for vendor advisories and patch information. Affected products include: Annigroup 5 In 1 Xvr Firmware, Annigroup 5 In 1 Xvr.