Information disclosure in Hikvision DVR/NVR Firmware - CVE-2020-7057
Published: January 14, 2020 / Updated: November 20, 2020
Hikvision DVR/NVR Firmware
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the Hikvision DVR DS-7204HGHI-F1 V4.0.1 build 180903 web version sends different responses for failed ISAPI/Security/sessionLogin/capabilities login attempts depending on whether the user account exists. A remote attacker can gain perform a brute-force attack and guess valid usernames.