CVE-2025-1739
HIGHTrivision Camera NC227WF v5.8.0 - Auth Bypass
Title source: llmDescription
An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vulnerability allows an attacker to retrieve administrator's credentials in cleartext by sending a request against the server using curl with random credentials to "/en/player/activex_pal.asp" and successfully authenticating the application.
Exploits (1)
Scores
CVSS v3
7.1
EPSS
0.0004
EPSS Percentile
12.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Details
CWE
CWE-288
Status
published
Products (1)
Trivision/Camera NC227WF
5.8.0
Published
Feb 27, 2025
Tracked Since
Feb 18, 2026