Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25240. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit leverages an unauthenticated stream disclosure vulnerability in Rifatron DVR devices by accessing the animate.cgi script through the Mobile Web Viewer module. It captures snapshots and renders them into a video file, demonstrating unauthorized access to live streams.
Description
Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.
Exploits (1)
This exploit leverages an unauthenticated stream disclosure vulnerability in Rifatron DVR devices by accessing the animate.cgi script through the Mobile Web Viewer module. It captures snapshots and renders them into a video file, demonstrating unauthorized access to live streams.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H