Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-47710. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated information disclosure vulnerability in COMMAX Smart Home Ruvie CCTV Bridge DVR Service, where RTSP credentials are exposed in plain-text via an HTTP request to the `/overview.asp` endpoint.
Description
COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploiting the /overview.asp endpoint. Attackers can access sensitive information, including login credentials and DVR settings, by submitting a GET request to this endpoint.
Exploits (1)
This exploit demonstrates an unauthenticated information disclosure vulnerability in COMMAX Smart Home Ruvie CCTV Bridge DVR Service, where RTSP credentials are exposed in plain-text via an HTTP request to the `/overview.asp` endpoint.
References (4)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N