CVE-2023-3704

MEDIUM

Cpplusworld Cp-uvr-1601e1-hc Firmware - Improper Input Validation

Title source: rule
STIX 2.1

Description

The vulnerability exists in CP-Plus DVR due to an improper input validation within the web-based management interface of the affected products. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this vulnerability could allow the remote attacker to change system time of the targeted device.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0053
EPSS Percentile 40.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (9)
cpplusworld/cp-uvr-0401l1-4kh_firmware < 4.000.00at008.0.0.r20230302
cpplusworld/cp-uvr-0401l1b-4kh_firmware < 4.000.00at008.0.0.r20230302
cpplusworld/cp-uvr-0801f1-hc_firmware < 4.000.00at008.0.0.r20230302
cpplusworld/cp-uvr-0801k1-h_firmware < 4.000.00at008.0.0.r20230302
cpplusworld/cp-uvr-0801k1b-h_firmware < 4.000.00at008.0.0.r20230302
cpplusworld/cp-uvr-0808k1-h_firmware < 4.000.00at008.0.0.r20230302
cpplusworld/cp-uvr-1601e1-h_firmware < 4.000.00at008.0.0.r20230302
cpplusworld/cp-uvr-1601e1-hc_firmware < 4.000.00at008.0.0.r20230302
cpplusworld/cp-uvr-1601e2-h_firmware < 4.000.00at008.0.0.r20230302
Published Aug 24, 2023
Tracked Since Feb 18, 2026