ID:9251 - Exploit for Improper authentication in TBK DVR4104 and TBK DVR4216 - CVE-2018-9995

 
Main Vulnerability Database Exploits ID:9251 - Exploit for Improper authentication in TBK DVR4104 and TBK DVR4216 - CVE-2018-9995

ID:9251 - Exploit for Improper authentication in TBK DVR4104 and TBK DVR4216 - CVE-2018-9995

Published: August 20, 2023


Vulnerability identifier: #VU12890
Vulnerability risk: Low
CVE-ID: CVE-2018-9995
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
TBK DVR4104
TBK DVR4216

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to improper authentication. A remote attacker can bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.

Remediation

Install update from vendor's website.