Incomplete in the CWE catalog · 23 CVEs mapped
The product stores a password in a configuration file that might be accessible to actors who do not know the password.
Hisilicon HiIpcam V100R003 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by exploiting directory listing in the cgi-bin directory. Attackers can request the getadslattr.cgi endpoint to retrieve ADSL credentials and network configuration parameters including usernames, passwords, and DNS settings.
A vulnerability was determined in TaleLin Lin-CMS up to 0.6.0. This affects an unknown part of the file /tests/config.py of the component Tests Folder. This manipulation of the argument username/password causes password in configuration file. The attack is possible to be carried out remotely. The complexity of an attack is rather high. It is indicated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized.
⚡ A single unauthenticated GET request is all it takes to access sensitive system configurations in MiniDVBLinux 5.4! This vulnerability is like leaving the blueprints of your house unattended on the front porch, inviting anyone to take a peek inside. 🔓 Think of it as a delivery driver who, instead of checking the address, just hands over all the confidential documents in the package to anyone who asks. The backup download endpoint can be exploited without any identity verification, making it alarmingly easy for attackers to grab sensitive info. An attacker could retrieve the entire system configuration archive, uncovering sensitive credentials and potentially gaining full control over the system. This could lead to devastating consequences, like unauthorized access to critical services or data breaches that affect the entire organization.