CVE-2019-12919

MEDIUM

Cylan Clever Dog Smart Camera Panoram... - Missing Authentication

Title source: rule
STIX 2.1

Description

On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal SD card via the HTTP service on port 8000. The HTTP web server on the camera allows anyone to view or download the video archive recorded and saved on the external memory card attached to the device.

Exploits (1)

exploitdb WRITEUP
by Alex Akinbi · textwebappshardware
https://www.exploit-db.com/exploits/46993

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 22.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-306
Status published
Products (2)
cylan/clever_dog_smart_camera_panorama_dog-2w_firmware
cylan/clever_dog_smart_camera_plus_dog-2w-v4_firmware
Published Jun 20, 2019
Tracked Since Feb 18, 2026