CVE-2019-10710

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/04/2019
Last modified:
24/08/2020

Description

Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a network's cleartext WiFi credentials via a specific HTTP request. This affects certain devices labeled as HI3510, HI3518, LOOSAFE, LEVCOECAM, Sywstoda, BESDER, WUSONGLUSAN, GADINAN, Unitoptek, ESCAM, etc.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hisilicon:hi3510_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hisilicon:hi3510:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools