CVE-2020-24219
HIGH EXPLOITEDURayTech IPTV/H.264/H.265 <1.97 - Path Traversal
Title source: llmExploitation Summary
CVE-2020-24219 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Alexei Kojenov.
AI-analyzed exploit summary This exploit leverages a path traversal vulnerability in HiSilicon video encoders to disclose arbitrary files without authentication. It uses a crafted HTTP request to traverse directories and access files outside the intended directory structure.
Description
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.
Exploits (1)
This exploit leverages a path traversal vulnerability in HiSilicon video encoders to disclose arbitrary files without authentication. It uses a crafted HTTP request to traverse directories and access files outside the intended directory structure.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N