CVE-2018-10676

CeNova, Night OWL, Novo, Pulnix, QSee, Securus, and TBK Vision DVR devices allow remote attackers to download a file and obtain sensitive credential information via a direct request for the download.rsp URI.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tbkvision:tbk-dvr4216_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tbkvision:tbk-dvr4216:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tbkvision:tbk-dvr4104_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tbkvision:tbk-dvr4104:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:41

Type Values Removed Values Added
References () http://misteralfa-hack.blogspot.cl/2018/05/0day-dvr-multivendor.html - Exploit, Third Party Advisory () http://misteralfa-hack.blogspot.cl/2018/05/0day-dvr-multivendor.html - Exploit, Third Party Advisory

Information

Published : 2018-05-02 18:29

Updated : 2024-11-21 03:41


NVD link : CVE-2018-10676

Mitre link : CVE-2018-10676

CVE.ORG link : CVE-2018-10676


JSON object : View

Products Affected

tbkvision

  • tbk-dvr4104
  • tbk-dvr4216
  • tbk-dvr4216_firmware
  • tbk-dvr4104_firmware