Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-67159 — Vatilon-based IP camera firmware allows authentication bypass and plaintext credential exposure via web.cgi API requests. | Kitploit
Tools/GitHubGitHub/remenis/cve-2025-67159
IoT SecurityVulnerability AnalysisExploitationWeb SecurityHardware & IoT SecurityAuthentication
GitHubremenis/cve-2025-67159

CVE-2025-67159

Vatilon-based IP camera firmware allows authentication bypass and plaintext credential exposure via web.cgi API requests.

View Repository
109 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-67159 — Vatilon-based IP Cameras

Summary

Vatilon-based IP camera firmware contains an authentication bypass and plaintext credential exposure vulnerability in the /cgi-bin/web.cgi API. The web interface processes requests containing username and password parameters in plaintext without validating authentication state or session context, allowing unauthenticated attackers to retrieve sensitive device information and administrative data.

Vulnerability type: Incorrect Access Control / Improper Authentication
Impact: Remote Information Disclosure, Privilege Escalation
CVSS v3.1: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)


Affected Devices (Observed)

VendorProduct / NotesFirmware Version
VatilonIP cameras (observed brand: JIENUO / devtype=PA4)V1.12.37-20240124 (uboot-2016-20, kernel linux-4.9-12)

Other devices using the same Vatilon firmware may also be affected.


Proof-of-Concept Disclosure Notice

Reproduction details, packet captures, and raw request/response data are withheld from public disclosure due to the high risk of abuse. Authorized parties (vendors, CERTs, CNAs) may request additional technical details after verification.


Additional Observations

  • The /cgi-bin/web.cgi endpoint accepts username and password parameters via HTTP GET requests without enforcing authentication or session validation.
  • Credentials are transmitted in plaintext and are visible in network traffic and browser developer tools.
  • Direct access to /view/player.html can trigger unauthenticated API requests to /cgi-bin/web.cgi, even without a valid login session.
  • The web application appears to rely on client-side state rather than server-side authentication enforcement.

Impact

  • Plaintext administrator credentials can be exposed to unauthenticated attackers.
  • Attackers can retrieve device configuration and sensitive information remotely.
  • The vulnerability enables unauthorized access and may lead to full device compromise.
  • The issue can be exploited remotely without user interaction.

Mitigation / Recommendations

  1. Enforce server-side authentication and session validation for all /cgi-bin/web.cgi requests.
  2. Stop accepting plaintext credentials in URL parameters; use secure authentication mechanisms.
  3. Ensure that all web interface components require a valid authenticated session.
  4. Remove sensitive information from API responses.
  5. Apply firmware updates provided by the vendor when available.
  6. Restrict access to the device web interface using network-level controls.

References

  • NVD Entry
  • CVE.org Entry

요약

Vatilon 기반 IP 카메라 펌웨어에서 /cgi-bin/web.cgi API 요청에 대해 인증 및 세션 검증이 수행되지 않는 취약점이 확인되었습니다.
이로 인해 공격자는 인증되지 않은 상태에서도 username과 password 파라미터를 포함한 요청을 전송할 수 있으며, 해당 자격 증명이 평문으로 노출되고 민감한 장치 정보에 접근할 수 있습니다.

취약점 유형: 접근 제어 불충분 / 인증 부적절
영향: 원격 정보 노출, 권한 상승
CVSS v3.1: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)


영향 대상 장비 (확인된 사례)

제조사제품펌웨어 버전
VatilonIP cameras (observed brand: JIENUO / devtype=PA4)V1.12.37-20240124 (uboot-2016-20, kernel linux-4.9-12)

개념 증명(재현 자료) 비공개 안내

재현 절차 및 원본 증거(PoC 요청, PCAP, 브라우저 네트워크 로그 등)는 악용 위험으로 인해 공개하지 않습니다. 벤더, CERT, CNA 등 공인 기관은 검증 후 추가 기술 정보를 요청할 수 있습니다.


추가 관찰사항

  • 웹 인터페이스는 서버 측 인증 검증 없이 클라이언트 요청을 신뢰합니다.
  • 스트리밍 인터페이스(/view/player.html) 접근만으로도 인증되지 않은 API 호출이 발생할 수 있습니다.

영향

  • 인증되지 않은 상태에서 장치 API 접근 가능
  • 관리자 자격 증명 평문 노출 가능
  • 원격 공격을 통한 장치 설정 유출 및 추가 침해 가능성 증가

완화 권고

  1. 모든 API 요청에 대해 서버 측 인증 및 세션 검증을 강제하십시오.
  2. 평문 자격 증명 전달 방식을 제거하십시오.
  3. 인증되지 않은 웹 UI 접근을 차단하십시오.
  4. 벤더에서 제공하는 보안 업데이트를 적용하십시오.
  5. 비정상적인 웹 요청 및 접근 패턴을 모니터링하십시오.
Download Tool