vendor:
DVR
by:
RAT - ThiefKing
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: DVR
Affected Version From: V2.3.1 build20160927
Affected Version To: V3.0.0 build20161206
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: V2.3.1 build20160927, V3.0.0 build20161206
2017
HBGK DVR V3.0.0 build20161206 – Authentication Bypass
Any registered user can login when edit cookie userInfo. When login successful, DVR saves cookie: userInfo + webport with value: base64 encode (user:pass). But Dvr does not check pass with cookie. When not yet login, you add a cookie: userInfoXX (xx : web port) with value base64 encode (admin: any words). And go url: http://dvr-domain.dynns.com:XX/doc/page/main.asp. It will Authentication Bypass.
Mitigation:
Update to Firmware version V3.0.0 build20170925