CVE-2019-25465

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
11/03/2026
Last modified:
15/04/2026

Description

Hisilicon HiIpcam V100R003 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by exploiting directory listing in the cgi-bin directory. Attackers can request the getadslattr.cgi endpoint to retrieve ADSL credentials and network configuration parameters including usernames, passwords, and DNS settings.