CVE-2020-36925
Severity CVSS v4.0:
HIGH
Type:
CWE-331
Insufficient Entropy
Publication date:
06/01/2026
Last modified:
06/01/2026
Description
Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://cxsecurity.com/issue/WLB-2020120170
- https://exchange.xforce.ibmcloud.com/vulnerabilities/193750
- https://exchange.xforce.ibmcloud.com/vulnerabilities/194139
- https://packetstorm.news/files/id/160718
- https://www.arteco-global.com
- https://www.exploit-db.com/exploits/49348
- https://www.vulncheck.com/advisories/arteco-web-client-dvrnvr-session-id-brute-force-authentication-bypass
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5613.php



