packetstormsecurity.com
http://packetstormsecurity.com/files/159595/HiSilicon-Video-Encoder-1.97-File-Disclosure-Path-Traversal.html CVE-2020-24219
HIGH
szuray iptv\/h.264_video_encoder_firmware Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2020-24219 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 4, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
iptv\/h.264_video_encoder_firmwareBrowse szuray / iptv\/h.264_video_encoder_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBHiSilicon Video Encoders - Unauthenticated file disclosure via path traversalExploitDB exploitby Alexei KojenovNot analyzed1 file
References
4kojenov.com
https://kojenov.com/2020-09-15-hisilicon-encoder-vulnerabilities nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-24219 kb.cert.org
https://www.kb.cert.org/vuls/id/896979