DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the /tmpfs/config_backup.bin resource.
References
Configurations
No configuration.
History
07 Feb 2026, 00:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-07 00:15
Updated : 2026-02-09 16:08
NVD link : CVE-2020-37157
Mitre link : CVE-2020-37157
CVE.ORG link : CVE-2020-37157
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
