CVE-2025-67159
HIGHVatilon PA4 Firmware v1.12.37-20240124 - Cleartext Transmission of Sensitive Information
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-67159. PoCs published by Remenis.
AI-analyzed exploit summary The repository describes an authentication bypass and plaintext credential exposure vulnerability in Vatilon-based IP cameras. The vulnerability allows unauthenticated attackers to retrieve sensitive device information and administrative data via the `/cgi-bin/web.cgi` API.
Description
Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.
Exploits (1)
The repository describes an authentication bypass and plaintext credential exposure vulnerability in Vatilon-based IP cameras. The vulnerability allows unauthenticated attackers to retrieve sensitive device information and administrative data via the `/cgi-bin/web.cgi` API.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N