CVE-2013-3540
AirLive OD-2025HD OD-2060HD POE100HD POE200HD POE250HD POE2600HD - Cross-Site Request Forgery in User Group Management
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-3540.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Airlive devices, including CSRF, path traversal, information exposure, and DoS. It provides functional PoC URLs and a Python script for testing the DoS vulnerability.
Description
Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/usrgrp.cgi in AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in Airlive devices, including CSRF, path traversal, information exposure, and DoS. It provides functional PoC URLs and a Python script for testing the DoS vulnerability.