An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vulnerability allows an attacker to retrieve administrator's credentials in cleartext by sending a request against the server using curl with random credentials to "/en/player/activex_pal.asp" and successfully authenticating the application.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Feb 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-598 | CWE-288 |
Thu, 27 Feb 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vulnerability allows an attacker to retrieve administrator's credentials in cleartext by sending a request against the server using curl with random credentials to "/en/player/activex_pal.asp" and successfully authenticating the application. | |
| Title | Multiple vulnerabilities in Trivision Camera NC227WF | |
| Weaknesses | CWE-598 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-02-27T12:45:26.314Z
Updated: 2025-02-27T14:24:12.502Z
Reserved: 2025-02-27T08:34:32.796Z
Link: CVE-2025-1739
Updated: 2025-02-27T14:24:09.442Z
Status : Received
Published: 2025-02-27T13:15:11.883
Modified: 2025-02-27T13:15:11.883
Link: CVE-2025-1739
No data.