CVE-2020-36925

CRITICAL

Arteco Web Client DVR/NVR - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-36925. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit performs a brute-force attack on the 'SessionId' cookie in Arteco Web Client DVR/NVR systems to bypass authentication and hijack valid sessions. It iterates through a range of possible session IDs and checks for a valid response to determine successful session hijacking.

Description

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · pythonwebappswindows
https://www.exploit-db.com/exploits/49348

This exploit performs a brute-force attack on the 'SessionId' cookie in Arteco Web Client DVR/NVR systems to bypass authentication and hijack valid sessions. It iterates through a range of possible session IDs and checks for a valid response to determine successful session hijacking.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Arteco Web Client DVR/NVR (version not specified)
No auth needed
Prerequisites: Network access to the target system · Knowledge of the target IP address
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Various Sources product
https://www.arteco-global.com
Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2020-5613.php
Third Party Advisory, VDB Entry vdb-entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/193750
Third Party Advisory, VDB Entry vdb-entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/194139
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/49348

Scores

CVSS v3 9.8
EPSS 0.0060
EPSS Percentile 43.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-331
Status published
Published Jan 06, 2026
Tracked Since Feb 18, 2026