CVE-2022-47070

NVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the server twice. In the second package, the server will return the correct password information.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:nvs365:nvs-365-v01_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvs365:nvs-365-v01:-:*:*:*:*:*:*:*

History

26 Mar 2025, 16:15

Type Values Removed Values Added
CWE CWE-200

21 Nov 2024, 07:31

Type Values Removed Values Added
References () https://github.com/Sylon001/NVS-365-Camera/tree/master/NVS365%20Network%20Video%20Server%20Password%20Information%20Unauthorized%20Access%20Vulnerability - Exploit, Third Party Advisory () https://github.com/Sylon001/NVS-365-Camera/tree/master/NVS365%20Network%20Video%20Server%20Password%20Information%20Unauthorized%20Access%20Vulnerability - Exploit, Third Party Advisory
References () https://github.com/Sylon001/NVS365/tree/main/NVS-365-V01%E6%91%84%E5%83%8F%E5%A4%B4%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E5%AF%86%E7%A0%81 - Broken Link () https://github.com/Sylon001/NVS365/tree/main/NVS-365-V01%E6%91%84%E5%83%8F%E5%A4%B4%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E5%AF%86%E7%A0%81 - Broken Link

03 Feb 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-02-03 21:15

Updated : 2025-03-26 16:15


NVD link : CVE-2022-47070

Mitre link : CVE-2022-47070

CVE.ORG link : CVE-2022-47070


JSON object : View

Products Affected

nvs365

  • nvs-365-v01_firmware
  • nvs-365-v01
CWE
NVD-CWE-Other CWE-200

Exposure of Sensitive Information to an Unauthorized Actor