Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5470 | An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vulnerability allows an attacker to retrieve administrator's credentials in cleartext by sending a request against the server using curl with random credentials to "/en/player/activex_pal.asp" and successfully authenticating the application. |
Solution
There is no reported solution at this time.
Workaround
No workaround given by the vendor.
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Feb 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-598 | CWE-288 |
Thu, 27 Feb 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vulnerability allows an attacker to retrieve administrator's credentials in cleartext by sending a request against the server using curl with random credentials to "/en/player/activex_pal.asp" and successfully authenticating the application. | |
| Title | Multiple vulnerabilities in Trivision Camera NC227WF | |
| Weaknesses | CWE-598 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-02-27T14:24:12.502Z
Reserved: 2025-02-27T08:34:32.796Z
Link: CVE-2025-1739
Updated: 2025-02-27T14:24:09.442Z
Status : Received
Published: 2025-02-27T13:15:11.883
Modified: 2025-02-27T13:15:11.883
Link: CVE-2025-1739
No data.
OpenCVE Enrichment
No data.
EUVD