Impact
The vulnerability resides in the Snapshot Endpoint component of wvp-GB28181-pro, specifically the PlayController.java file. By manipulating the deviceId or channelId parameters the attacker may trigger directory traversal, resulting in reading of arbitrary files from the underlying filesystem. The effect is the unauthorized disclosure of potentially sensitive data stored on the host. No denial of service or privilege escalation is described in the CVE data.
Affected Systems
The affected system is the 648540858 wvp-GB28181-pro application, version 2.7.4‑20260107. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 reflects medium severity. No EPSS score is publicly available and the vulnerability is not listed in the CISA KEV catalog. The CVE description states that an exploit is publicly available and might be used. The likely attack vector is remote, with an attacker sending crafted requests to the deviceId or channelId arguments over the network. Successful exploitation would allow the attacker to read arbitrary files, potentially including configuration, credentials, or other confidential data.
OpenCVE Enrichment