Path Traversal Vulnerability in Dahua IPC Cameras
CVE-2024-13130
What is CVE-2024-13130?
A vulnerability exists in certain Dahua IP cameras that enables path traversal through the web interface. By manipulating requests, an attacker can exploit an unknown functionality within the file ../mtd/Config/Sha1Account1, leading to unauthorized access to sensitive file directories. This vulnerability can be exploited remotely, posing significant security risks to users and potentially exposing their systems to further attacks. It is important for users of the affected models to implement immediate security measures and stay informed about any available patches or updates.
Affected Version(s)
IPC-HDW1200S 20241222
IPC-HFW1200S 20241222
IPC-HFW2300R-Z 20241222
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published