9.8

CVE-2018-10734

Exploit
KONGTOP DVR devices A303, A403, D303, D305, and D403 contain a backdoor that prints the login password via a Print_Password function call in certain circumstances.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kongtop ≫ D303 Firmware Version -
   Kongtop ≫ D303 Version -
Kongtop ≫ D305 Firmware Version -
   Kongtop ≫ D305 Version -
Kongtop ≫ D403 Firmware Version -
   Kongtop ≫ D403 Version -
Kongtop ≫ A303 Firmware Version -
   Kongtop ≫ A303 Version -
Kongtop ≫ A403 Firmware Version -
   Kongtop ≫ A403 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.87% 0.766
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://github.com/hucmosin/MyBook/blob/master/KONGTOP_DVR_devices_vulnerability_report-CVE-2018-10734.pdf
Third Party Advisory
https://github.com/hucmosin/MyBook/blob/master/fu/DVR.pdf
Third Party Advisory
https://github.com/hucmosin/Python_Small_Tool/blob/master/other/DVR_POC.py
Third Party Advisory
Exploit