Description
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.
Published: 2020-10-06
Score: 7.5 High
EPSS: 25.2% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Szuray Iptv\/h.264 Video Encoder Firmware Iptv\/h.265 Video Encoder Firmware Uaioe264-1u Uaioe265-1u Uce264-1-mini Uce264-1wb-mini Uce264-4-1u Uce264-8-1u Uhae264-16 Uhae265-1-mini Uhae265-1wb-mini Uhae265-4-1u Uhce264-1 Uhce264-16p32 Uhce264-1p2 Uhce264-1p2-1u Uhce264-1s Uhce264-1w Uhce264-1ws Uhce264-4p8 Uhe264-1-4k Uhe264-16 Uhe264-16l-3u Uhe264-16s-2u Uhe264-1l Uhe264-1l-4k Uhe264-1lw Uhe264-1s Uhe264-1s-mini Uhe264-1w-mini Uhe264-1wb-4g Uhe264-1wb-mini Uhe264-1wbs-2b Uhe264-1wbs-mini Uhe264-1ws-mini Uhe264-2-1u Uhe264-4 Uhe264-4-1u Uhe264-4l-1u Uhe264-8 Uhe264-8-1u Uhe264-8l-3u Uhe264-8s-2u Uhe265-1 Uhe265-1-1u Uhe265-1-4k Uhe265-1-mini Uhe265-16-3u Uhe265-16l-3u Uhe265-1l Uhe265-1lw Uhe265-1s-4k Uhe265-1s-mini Uhe265-1w Uhe265-1w-4k Uhe265-1w-mini Uhe265-1wb-4g Uhe265-1wb-mini Uhe265-1wbs-mini Uhe265-2-1u Uhe265-4 Uhe265-4-1u Uhe265-4s Uhe265-4s-1u Uhe265-8-1u Uhe265-8l-3u Uhe265-8s-1u Uhse265-1u Use264-16-3u Use264-1l Use264-1l-1u Use264-1l-mini Use264-1lw Use264-1wb-l Use264-4l-1u Use264-8-1u Use265-1-1u Use265-1-mini Use265-16l-3u Use265-1l Use265-1l-1u Use265-1l-mini Use265-1lw Use265-1w-mini Use265-1wb-4g Use265-1wb-l Use265-1wb-mini Use265-2-1u Use265-4-1u Use265-4l-1u Use265-8-1u Uve264-1l Uve264-1lw Uve265-1 Uve265-1w
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T15:12:07.227Z

Reserved: 2020-08-13T00:00:00.000Z

Link: CVE-2020-24219

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-06T14:15:12.463

Modified: 2024-11-21T05:14:31.080

Link: CVE-2020-24219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses