Impact
The VIN‑DS783E‑E6 IP camera model contains an Arbitrary File Read flaw, known as Relative Path Traversal, that permits authenticated remote attackers to download any file on the system.
Affected Systems
This vulnerability affects devices running the Vacron VIN‑DS783E‑E6 firmware. No specific firmware revision range is provided, but any system running this model is potentially impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while an EPSS score of less than 1% shows a low probability of exploitation. The flaw is not yet listed in CISA’s KEV catalog. Attackers would first need valid user credentials on the camera and then can use the path‑traversal technique to expose sensitive files, risking confidentiality loss.
OpenCVE Enrichment