CVE-2019-14700

HIGH

MicroDigital N-series <6400.0.8.5 - Path Traversal

Title source: llm
STIX 2.1

Description

An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. There is disclosure of the existence of arbitrary files via Path Traversal in HTTPD. This occurs because the filename specified in the TZ parameter is accessed with a substantial delay if that file exists.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_misc
https://www.microdigital.ru/
Vendor Advisory x_refsource_misc
http://www.microdigital.co.kr/
Third Party Advisory x_refsource_misc
https://pastebin.com/PSyqqs1g

Scores

CVSS v3 7.5
EPSS 0.0208
EPSS Percentile 79.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (3)
microdigital/mdc-n2190v_firmware < 6400.0.8.5
microdigital/mdc-n4090_firmware < 6400.0.8.5
microdigital/mdc-n4090w_firmware < 6400.0.8.5
Published Aug 06, 2019
Tracked Since Feb 18, 2026