CVE-2013-3541

AirLive WL2600CAM - Path Traversal via fileread READ.filePath Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-3541.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Airlive devices, including relative path traversal (CVE-2013-3541) and DoS (CVE-2013-3691). It provides functional PoC URLs and a Python script for testing the DoS vulnerability.

Description

Directory traversal vulnerability in cgi-bin/admin/fileread in AirLive WL2600CAM and possibly other camera models allows remote attackers to read arbitrary files via a .. (dot dot) in the READ.filePath parameter.

Exploits (1)

exploitdb WORKING POC
webappshardware
https://www.exploit-db.com/exploits/26174

The exploit demonstrates multiple vulnerabilities in Airlive devices, including relative path traversal (CVE-2013-3541) and DoS (CVE-2013-3691). It provides functional PoC URLs and a Python script for testing the DoS vulnerability.

Classification
Working Poc 90%
Attack Type
Info Leak | Dos
Complexity
Trivial
Reliability
Reliable
Target: Airlive WL2600CAM, POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD
No auth needed
Prerequisites: Network access to the target device
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2013/Jun/84

Scores

EPSS 0.0893
EPSS Percentile 94.6%

Details

CWE
CWE-22
Status published
Products (1)
ovislink/airlive_wl2600cam
Published Oct 04, 2013
Tracked Since Feb 18, 2026