JVC VN-T IP-Camera Directory Traversal via check.cgi
Vulnerability Description
JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-15055
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Yakir Wizman
References
- https://www.exploit-db.com/exploits/40282
- https://web.archive.org/web/20170713051843/http://www.black-rose.ml/2016/08/analyzing-security-cameras-products.html
- http://pro.jvc.com/prof/attributes/tech_desc.jsp?model_id=MDL102145&feature_id=02
- https://www.vulncheck.com/advisories/jvc-vnt-ip-camera-directory-traversal-via-check-cgi
Affected Vendor
JVC (JVCKENWOOD)
View all reports →