Advertisement






VelotiSmart WiFi B-380 Camera Directory Traversal

CVE Category Price Severity
CVE-2021-39368 CWE-22 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2018-07-17
CPE
cpe:No CPE associated with this exploit
CVSS EPSS EPSSP
CVSS:4.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H 0.05687 0.56716

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018070173

Below is a copy:

VelotiSmart WiFi B-380 Camera Directory Traversal
Title: Vulnerability in VelotiSmart Wifi - Directory Traversal
Date: 12-07-2018
Scope: Directory Traversal
Platforms: Unix
Author: Miguel Mendez Z
Vendor: VelotiSmart
Version: B380
CVE: CVE-2018a14064
 
 
Vulnerability description
-------------------------
- The vulnerability that affects the device is LFI type in the uc-http service 1.0.0. What allows to obtain information of configurations, wireless scanned networks, sensitive directories, etc. Of the device.
 
Vulnerable variable:
http://domain:80/../../etc/passwd
 
Exploit link:
https://github.com/s1kr10s/ExploitVelotiSmart
 
Poc:
https://medium.com/@s1kr10s/velotismart-0day-ca5056bcdcac

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum