Hisilicon HiIpcam V100R003 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by exploiting directory listing in the cgi-bin directory. Attackers can request the getadslattr.cgi endpoint to retrieve ADSL credentials and network configuration parameters including usernames, passwords, and DNS settings.
References
Configurations
No configuration.
History
11 Mar 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
11 Mar 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-11 19:15
Updated : 2026-03-12 21:08
NVD link : CVE-2019-25465
Mitre link : CVE-2019-25465
CVE.ORG link : CVE-2019-25465
JSON object : View
Products Affected
No product.
CWE
CWE-260
Password in Configuration File
