CVE-2022-24610

HIGH

Alecto DVC-215IP <63.1.1.173 - Info Disclosure

Title source: llm

Description

Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi passphrase hidden, but by editing/removing the style of the password field the password becomes visible which grants access to an internal network connected to the camera.

Scores

CVSS v3 8.6
EPSS 0.0028
EPSS Percentile 50.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (1)

alecto/dvc-215ip_firmware < 63.1.1.173

Timeline

Published Feb 24, 2022
Tracked Since Feb 18, 2026