AVer PTC310UV2 Information Disclosure Vulnerability

Vulnerability

A vulnerability in the AVer PTC310UV2 camera, running firmware version 0.1.0000.59, allows remote attackers to obtain sensitive information through crafted requests. This issue arises from the web interface, where authentication is improperly handled by exposing usernames and passwords in unencrypted network traffic. The vulnerability was discovered during a penetration test, revealing flaws in the application's client-side authentication process.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive credentials, such as usernames and passwords, which are exposed in clear text over the network.

Reproduction

The vulnerability can be reproduced by sending a request to the camera's web interface that triggers the authentication mechanism. The application will pull credentials from a specified endpoint and return them in an unencrypted format. Monitoring the network traffic will reveal the exposed usernames and passwords.

Added: Jul 30, 2025, 5:17 PM
Updated: Jul 30, 2025, 7:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.