cve/2019/CVE-2019-7315.md
2024-06-18 02:51:15 +02:00

866 B

CVE-2019-7315

Description

Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal via the web interface, as demonstrated by reading /etc/shadow. NOTE: this product is discontinued, and its final firmware version has this vulnerability (4.x versions exist only for other Genie Access products).

POC

Reference

Github