vendor:
N100 H.264 VGA IP Camera
by:
Gjoko 'LiquidWorm' Krstic
8.8
CVSS
HIGH
Authenticated File Disclosure
434
CWE
Product Name: N100 H.264 VGA IP Camera
Affected Version From: M2.1.6.04C014
Affected Version To: M2.1.6.04C014
Patch Exists: NO
Related CWE: N/A
CPE: h:beward:n100_h.264_vga_ip_camera
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Boa/0.94.14rc21, Farady ARM Linux 2.6
2019
BEWARD N100 H.264 VGA IP Camera M2.1.6 Arbitrary File Disclosure
The N100 compact color IP camera suffers from an authenticated file disclosure vulnerability. Input passed via the 'READ.filePath' parameter in fileread script is not properly verified before being used to read files. This can be exploited to disclose the contents of arbitrary files via absolute path or via the SendCGICMD API.
Mitigation:
Ensure that user input is properly validated and sanitized before being used to read files.