CVE-2019-3423

permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can construct a URL for directory traversal and access to other unauthorized files or resources.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ztehome:c520v21_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ztehome:c520v21:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:42

Type Values Removed Values Added
References () http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1011842 - Vendor Advisory () http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1011842 - Vendor Advisory

Information

Published : 2019-11-18 19:15

Updated : 2024-11-21 04:42


NVD link : CVE-2019-3423

Mitre link : CVE-2019-3423

CVE.ORG link : CVE-2019-3423


JSON object : View

Products Affected

ztehome

  • c520v21
  • c520v21_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')