CVE-2019-25465
HIGHHisilicon HiIpcam V100R003 - Path Traversal
Title source: llmDescription
Hisilicon HiIpcam V100R003 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by exploiting directory listing in the cgi-bin directory. Attackers can request the getadslattr.cgi endpoint to retrieve ADSL credentials and network configuration parameters including usernames, passwords, and DNS settings.
Exploits (1)
Scores
CVSS v3
7.5
EPSS
0.0040
EPSS Percentile
60.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-260
Status
published
Products (1)
Hisilicon/HiIpcam
V100R003
Published
Mar 11, 2026
Tracked Since
Mar 12, 2026