Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2022-47618
Disclosure Date: December 29, 2022 (last updated October 08, 2023)
Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service.
0
Attacker Value
Unknown
CVE-2021-30167
Disclosure Date: April 28, 2021 (last updated November 28, 2024)
The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL parameters and further amend user’s information and escalate privileges to control the devices.
0
Attacker Value
Unknown
CVE-2021-30168
Disclosure Date: April 28, 2021 (last updated November 28, 2024)
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices.
0
Attacker Value
Unknown
CVE-2021-30166
Disclosure Date: April 28, 2021 (last updated November 28, 2024)
The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.
0
Attacker Value
Unknown
CVE-2021-30169
Disclosure Date: April 28, 2021 (last updated November 28, 2024)
The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential.
0
Attacker Value
Unknown
CVE-2001-1000
Disclosure Date: September 07, 2001 (last updated February 22, 2025)
rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file.
0
Attacker Value
Unknown
CVE-2001-0534
Disclosure Date: July 21, 2001 (last updated February 22, 2025)
Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands.
0