vendor:
C2S DVR
by:
Yakir Wizman
7.5
CVSS
HIGH
Credentials Disclosure, Authentication bypass
CWE
Product Name: C2S DVR
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: IRDOME-II-C2S, IRBOX-II-C2S, DVR
2016
C2S DVR Management Remote Credentials Disclosure & Authentication Bypass
C2S DVR allows an unauthenticated user to disclose the username & password remotely by a simple request to the server page 'read.cgi?page=2'. Moreover, an attacker could easily access the password change page without any authentication, as the web application does not perform any session management.
Mitigation:
Implement proper authentication and session management in the C2S DVR management system.