
Vatilon-based IP camera firmware allows authentication bypass and plaintext credential exposure via web.cgi API requests.
Vatilon-based IP camera firmware contains an authentication bypass and plaintext credential
exposure vulnerability in the /cgi-bin/web.cgi API. The web interface processes requests
containing username and password parameters in plaintext without validating authentication
state or session context, allowing unauthenticated attackers to retrieve sensitive device
information and administrative data.
Vulnerability type: Incorrect Access Control / Improper Authentication
Impact: Remote Information Disclosure, Privilege Escalation
CVSS v3.1: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
| Vendor | Product / Notes | Firmware Version |
|---|---|---|
| Vatilon | IP cameras (observed brand: JIENUO / devtype=PA4) | V1.12.37-20240124 (uboot-2016-20, kernel linux-4.9-12) |
Other devices using the same Vatilon firmware may also be affected.
Reproduction details, packet captures, and raw request/response data are withheld from public disclosure due to the high risk of abuse. Authorized parties (vendors, CERTs, CNAs) may request additional technical details after verification.
/cgi-bin/web.cgi endpoint accepts username and password parameters via HTTP GET
requests without enforcing authentication or session validation./view/player.html can trigger unauthenticated API requests to
/cgi-bin/web.cgi, even without a valid login session./cgi-bin/web.cgi requests.Vatilon 기반 IP 카메라 펌웨어에서 /cgi-bin/web.cgi API 요청에 대해
인증 및 세션 검증이 수행되지 않는 취약점이 확인되었습니다.
이로 인해 공격자는 인증되지 않은 상태에서도 username과 password
파라미터를 포함한 요청을 전송할 수 있으며, 해당 자격 증명이 평문으로
노출되고 민감한 장치 정보에 접근할 수 있습니다.
취약점 유형: 접근 제어 불충분 / 인증 부적절
영향: 원격 정보 노출, 권한 상승
CVSS v3.1: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
| 제조사 | 제품 | 펌웨어 버전 |
|---|---|---|
| Vatilon | IP cameras (observed brand: JIENUO / devtype=PA4) | V1.12.37-20240124 (uboot-2016-20, kernel linux-4.9-12) |
재현 절차 및 원본 증거(PoC 요청, PCAP, 브라우저 네트워크 로그 등)는 악용 위험으로 인해 공개하지 않습니다. 벤더, CERT, CNA 등 공인 기관은 검증 후 추가 기술 정보를 요청할 수 있습니다.
/view/player.html) 접근만으로도 인증되지 않은
API 호출이 발생할 수 있습니다.