CVE-2021-26627

Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerability could allow to remote attackers to send the RTSP requests using ffplay command and lead to leakage a live image.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:qcp:qcp200w_firmware:-:*:*:*:*:android:*:*
cpe:2.3:o:qcp:qcp200w_firmware:-:*:*:*:*:windows:*:*
cpe:2.3:h:qcp:qcp200w:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:56

Type Values Removed Values Added
References () https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66663 - Third Party Advisory () https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66663 - Third Party Advisory

27 Apr 2022, 18:10

Type Values Removed Values Added
CPE cpe:2.3:o:qcp:qcp200w_firmware:-:*:*:*:*:windows:*:*
cpe:2.3:h:qcp:qcp200w:-:*:*:*:*:*:*:*
cpe:2.3:o:qcp:qcp200w_firmware:-:*:*:*:*:android:*:*
CWE CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
References (MISC) https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66663 - (MISC) https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=66663 - Third Party Advisory

19 Apr 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-19 21:15

Updated : 2024-11-21 05:56


NVD link : CVE-2021-26627

Mitre link : CVE-2021-26627

CVE.ORG link : CVE-2021-26627


JSON object : View

Products Affected

qcp

  • qcp200w_firmware
  • qcp200w
CWE
CWE-284

Improper Access Control

CWE-287

Improper Authentication