
Vatilon-based IP cameras expose internal web directories without authentication, leading to information disclosure.
Vatilon-based IP camera firmware exposes multiple internal web directories without requiring
authentication. When directory indexing is enabled on the embedded web server, unauthenticated
attackers can access directories such as /cgi-bin/, /view/, /css/, /img/, /img2/,
/js/, /js2/, and /onvif/, revealing internal scripts, configuration pages, and sensitive
implementation details.
This exposure allows attackers to study the internal structure of the web interface and can increase the impact of other vulnerabilities, such as authentication bypass or unauthorized configuration access.
Vulnerability type: Incorrect Access Control
Impact: Remote Information Disclosure
CVSS v3.1: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
| Vendor | Product / Notes | Firmware Version |
|---|---|---|
| Vatilon | IP cameras (observed brand: JIENUO / devtype=PA4) | V1.12.37-20240124 (uboot-2016-20, kernel linux-4.9-12) |
Other models using the same Vatilon firmware may also be affected.
Reproduction details and raw evidence are withheld from public disclosure due to potential abuse. Authorized parties (vendors, CERTs, CNAs) may request additional technical details after verification.
/view/, /cgi-bin/, /css/, /img/, /img2/, /js/, /js2/, and /onvif/.username and password fields into API request logic./view/player.html directly through exposed directories can cause the
browser to issue API requests that include cleartext credential values in network traffic./cgi-bin/web.cgi.Vatilon 기반 IP 카메라 펌웨어에서 인증 없이 내부 웹 디렉터리에 접근할 수 있는
취약점이 확인되었습니다.
공격자는 /cgi-bin/, /view/, /css/, /js/, /img/, /onvif/ 등의 디렉터리를
직접 열람할 수 있으며, 이를 통해 내부 구조, API 엔드포인트, 요청 파라미터 등의
민감한 구현 정보를 확인할 수 있습니다.
이 취약점은 단독으로는 설정 변경이나 코드 실행을 유발하지 않지만, 인증 우회와 같은 다른 취약점과 결합될 경우 공격 효율을 크게 높일 수 있습니다.
취약점 유형: 잘못된 접근 제어
영향: 원격 정보 노출
CVSS v3.1: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
| 제조사 | 제품 | 펌웨어 버전 |
|---|---|---|
| Vatilon | IP cameras (observed brand: JIENUO / devtype=PA4) | V1.12.37-20240124 (uboot-2016-20, kernel linux-4.9-12) |
재현 절차 및 원본 증거는 악용 위험으로 인해 공개하지 않습니다.
벤더, CERT, CNA 등 공인 기관은 검증 후 추가 기술 정보를 요청할 수 있습니다.