Smartwares Cameras Path Traversal Vulnerability
Vulnerability
A path traversal vulnerability has been identified in Smartwares cameras CIP-37210AT and C724IP, as well as other models sharing the same firmware, all through version 3.3.0. When an affected device is connected to a mobile app, it opens port 10000, allowing users to download photos by specifying file paths. However, the lack of directory access restrictions enables path traversal attacks, potentially leading to the download of sensitive information. The vendor has not responded to reports, leaving the patching status unclear, and newer firmware versions may also be vulnerable.
Impact
Exploitation of this vulnerability allows for unauthorized access to files outside the intended directory, potentially leading to the disclosure of sensitive information.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
