CVE-2019-25240

CRITICAL

Rifatron 5brid DVR - Unauthenticated Access

Title source: llm

Description

Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · bashwebappscgi
https://www.exploit-db.com/exploits/47368

Scores

CVSS v3 9.8
EPSS 0.0011
EPSS Percentile 29.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-306
Status draft

Timeline

Published Dec 24, 2025
Tracked Since Feb 18, 2026