Vulnerability Description
Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpoint on port 8080. Attackers can retrieve video stream data without authentication by directly accessing the specified endpoint on affected Akuvox doorphone and intercom devices.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Akuvox | S539 Firmware | 912.30.1.137 |
| Akuvox | S539 | - |
| Akuvox | S532 Firmware | 912.30.1.137 |
| Akuvox | S532 | - |
| Akuvox | X916 Firmware | 912.30.1.137 |
| Akuvox | X916 | - |
| Akuvox | X915 Firmware | 912.30.1.137 |
| Akuvox | X915 | - |
| Akuvox | X912 Firmware | 912.30.1.137 |
| Akuvox | X912 | - |
| Akuvox | R29 Firmware | 912.30.1.137 |
| Akuvox | R29 | - |
| Akuvox | R20K-2 Firmware | 912.30.1.137 |
| Akuvox | R20K-2 | - |
| Akuvox | R20A-2 Firmware | 912.30.1.137 |
| Akuvox | R20A-2 | - |
| Akuvox | C313W-2 Firmware | 912.30.1.137 |
| Akuvox | C313W-2 | - |
| Akuvox | Ns-2 Firmware | 912.30.1.137 |
| Akuvox | Ns-2 | - |
Related Weaknesses (CWE)
References
- https://packetstormsecurity.com/files/180262/Broken Link
- https://www.vulncheck.com/advisories/akuvox-smart-intercom-s-unauthenticated-vidThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5826.phpThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5826.phpThird Party Advisory
FAQ
What is CVE-2024-58336?
CVE-2024-58336 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpoint on port 8080. Attackers can retrieve...
How severe is CVE-2024-58336?
CVE-2024-58336 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-58336?
Check the references section above for vendor advisories and patch information. Affected products include: Akuvox S539 Firmware, Akuvox S539, Akuvox S532 Firmware, Akuvox S532, Akuvox X916 Firmware.