Revotech I6032W-FHW Authentication Bypass Vulnerability Allowing Privilege Escalation and Information Disclosure

Vulnerability

An authentication bypass vulnerability has been identified in the Revotech I6032W-FHW IP camera firmware, specifically in versions 1.0.0014 prior to 20210517. The vulnerability exists in the '/cgi-bin/jvsweb.cgi' endpoint, where the device fails to properly validate authentication fields in JSON-based API requests. This flaw allows unauthenticated attackers to access administrative API functions, retrieve sensitive information, and escalate privileges without valid credentials.

Impact

Exploitation of this vulnerability allows unauthorized access to administrative API functions, remote disclosure of sensitive user and account information, and unauthorized privilege escalation. Additionally, this vulnerability could be used as a stepping stone for further compromising the device.

Remediation

Users are advised to apply firmware updates provided by the vendor when available, restrict network access to the device management interface, and monitor and log abnormal or repeated access attempts to the '/cgi-bin/jvsweb.cgi' endpoint.

Added: Jan 2, 2026, 5:25 PM
Updated: Jan 2, 2026, 5:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.7
remediation
0.0
relevance
1.8
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.