9.8
CVSSv3

CVE-2018-10676

Published: 02/05/2018 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

CeNova, Night OWL, Novo, Pulnix, QSee, Securus, and TBK Vision DVR devices allow remote malicious users to download a file and obtain sensitive credential information via a direct request for the download.rsp URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tbkvision tbk-dvr4216_firmware -

tbkvision tbk-dvr4104_firmware -

Github Repositories

Exploitation framework for IP cameras

CamSploit v101 CamSploit is an exploiting tool that helps in the IP camera pentest It was developed using Dot Net Core (compatible with Windows and Linux), tested in windows 10 and Ubuntu 16 It has got a modular collection of exploits You can create your own modules to expands the currents exploits CamSploit is distributed under the GNU GPLv3 license In the next weeks, i

CamSploit v101 CamSploit is an exploiting tool that helps in the IP camera pentest It was developed using Dot Net Core (compatible with Windows and Linux), tested in windows 10 and Ubuntu 16 It has got a modular collection of exploits You can create your own modules to expands the currents exploits CamSploit is distributed under the GNU GPLv3 license In the next weeks, i