CVE-2018-10770

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
09/05/2018
Last modified:
14/06/2018

Description

download.rsp on ShenZhen Anni "5 in 1 XVR" devices allows remote attackers to download the configuration (without a login) to discover the password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:annigroup:5_in_1_xvr_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:annigroup:5_in_1_xvr:-:*:*:*:*:*:*:*