5.1

CVSS4.0

CVE-2019-25247 - Beward N100 H.264 VGA IP Camera M2.1.6 CSRF Add Admin Vulnerability

Beward N100 H.264 VGA IP Camera M2.1.6 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft a malicious web page with a hidden form to add an admin user by tricking a logged-in user into su…

📅 Published: Dec. 24, 2025, 7:28 p.m. 🔄 Last Modified: Dec. 24, 2025, 7:28 p.m.

7.1

CVSS4.0

CVE-2019-25246 - Beward N100 H.264 VGA IP Camera M2.1.6 Authenticated File Disclosure

Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to read arbitrary system files via the 'READ.filePath' parameter. Attackers can exploit the fileread script or SendCGICMD API to access sensitive files like /etc/passwd and /etc/issu…

📅 Published: Dec. 24, 2025, 7:28 p.m. 🔄 Last Modified: Dec. 24, 2025, 7:28 p.m.

8.5

CVSS4.0

CVE-2019-25245 - Ross Video DashBoard 8.5.1 Privilege Escalation via Insecure Permissions

Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files due to improper permission settings. Attackers can exploit the 'M' or 'C' flags for 'Authenticated Users' group to replace the DashBoard.exe binary with a maliciou…

📅 Published: Dec. 24, 2025, 7:27 p.m. 🔄 Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2019-25244 - Legrand BTicino Driver Manager F454 1.0.51 CSRF and Stored XSS Vulnerabilities

Legrand BTicino Driver Manager F454 1.0.51 contains multiple web vulnerabilities that allow attackers to perform administrative actions without proper request validation. Attackers can exploit cross-site request forgery to change passwords and inject stored cross-site scripting payloads through unv…

📅 Published: Dec. 24, 2025, 7:27 p.m. 🔄 Last Modified: Dec. 24, 2025, 7:27 p.m.

8.7

CVSS4.0

CVE-2019-25243 - FaceSentry 6.4.8 Authenticated Remote Command Injection via Ping Test

FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' paramet…

📅 Published: Dec. 24, 2025, 7:27 p.m. 🔄 Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2019-25242 - FaceSentry Access Control System 6.4.8 Cross-Site Request Forgery via Web Interface

FaceSentry Access Control System 6.4.8 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to change administrator passwords, add new admin users, or open access control doors by tr…

📅 Published: Dec. 24, 2025, 7:27 p.m. 🔄 Last Modified: Dec. 24, 2025, 7:27 p.m.

9.3

CVSS4.0

CVE-2019-25241 - FaceSentry Access Control System 6.4.8 Remote SSH Root Access

FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials for the wwwuser account. Attackers can leverage the insecure sudoers configuration to escalate privileges and gain root access by executing sudo commands without authentication.

📅 Published: Dec. 24, 2025, 7:27 p.m. 🔄 Last Modified: Dec. 24, 2025, 7:27 p.m.

8.7

CVSS4.0

CVE-2019-25240 - Rifatron 5brid DVR 5brid DVR (HD6-532/516, DX6-516/508/504, MX6-516/508/504, EH6-504) Unauthenticat…

Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.

📅 Published: Dec. 24, 2025, 7:27 p.m. 🔄 Last Modified: Dec. 24, 2025, 7:27 p.m.

8.7

CVSS4.0

CVE-2019-25239 - V-SOL GPON/EPON OLT Platform 2.03 Unauthenticated Configuration Download

V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers to download configuration files via direct object reference. Attackers can retrieve sensitive configuration data by sending HTTP GET requests to the usrcfg.conf endpoint, potenti…

📅 Published: Dec. 24, 2025, 7:27 p.m. 🔄 Last Modified: Dec. 24, 2025, 7:27 p.m.

5.1

CVSS4.0

CVE-2019-25238 - V-SOL GPON/EPON OLT Platform 2.03 Cross-Site Request Forgery Vulnerability

V-SOL GPON/EPON OLT Platform 2.03 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to create admin users, enable SSH, or modify system settings by tricking authenticated administ…

📅 Published: Dec. 24, 2025, 7:27 p.m. 🔄 Last Modified: Dec. 24, 2025, 7:27 p.m.
Total resulsts: 324360
Page 5 of 32,436
« previous page » next page
Filters