Show filters
274 Total Results
Displaying 81-90 of 274
Sort by:
Attacker Value
Unknown
CVE-2019-20466
Disclosure Date: April 02, 2021 (last updated February 22, 2025)
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A local attacker with the "default" account is capable of reading the /etc/passwd file, which contains a weakly hashed root password. By taking this hash and cracking it, the attacker can obtain root rights on the device.
0
Attacker Value
Unknown
CVE-2019-20463
Disclosure Date: April 02, 2021 (last updated July 30, 2024)
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A crash and reboot can be triggered by crafted IP traffic, as demonstrated by the Nikto vulnerability scanner. For example, sending the 111111 string to UDP port 20188 causes a reboot. To deny service for a long time period, the crafted IP traffic may be sent periodically.
0
Attacker Value
Unknown
CVE-2019-20464
Disclosure Date: April 02, 2021 (last updated February 22, 2025)
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. By default, a mobile application is used to stream over UDP. However, the device offers many more services that also enable streaming. Although the service used by the mobile application requires a password, the other streaming services do not. By initiating communication on the RTSP port, an attacker can obtain access to the video feed without authenticating.
0
Attacker Value
Unknown
CVE-2019-20465
Disclosure Date: April 02, 2021 (last updated July 30, 2024)
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. It is possible (using TELNET without a password) to control the camera's pan/zoom/tilt functionality.
0
Attacker Value
Unknown
CVE-2020-19643
Disclosure Date: March 30, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B via all fields in the FTP settings page to the "goform/formSetFtpCfg" settings page.
0
Attacker Value
Unknown
CVE-2020-19640
Disclosure Date: March 30, 2021 (last updated November 28, 2024)
An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. An unauthenticated attacker can reboot the device causing a Denial of Service, via a hidden reboot command to '/media/?action=cmd'.
0
Attacker Value
Unknown
CVE-2020-19641
Disclosure Date: March 30, 2021 (last updated February 22, 2025)
An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. Authenticated attackers with the "Operator" Privilege can gain admin privileges via a crafted request to '/goform/formUserMng'.
0
Attacker Value
Unknown
CVE-2020-19639
Disclosure Date: March 30, 2021 (last updated February 22, 2025)
Cross Site Request Forgery (CSRF) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B, via all fields to WebUI.
0
Attacker Value
Unknown
CVE-2020-19642
Disclosure Date: March 30, 2021 (last updated February 22, 2025)
An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitrary code via editing the 'recdata.db' file to call a specially crafted GoAhead ASP-file on the SD card.
0
Attacker Value
Unknown
CVE-2020-8765
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
Incorrect default permissions in the installer for the Intel(R) RealSense(TM) DCM may allow a privileged user to potentially enable escalation of privilege via local access.
0