Improper access control in AVTECH Corporation products - #VU48219
Published: November 9, 2020
IP camera
NVR
DVR
AVTECH Corporation
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions to scripts located in the "/cgi-bin/nobody" folder, e.g. "/cgi-bin/nobody/Machine.cgi". A remote non-authenticated attacker can send requests to the scrips in the folder and gain access to sensitive information.