DBPower C300 HD Camera - Remote Configuration Disclosure
Vulnerability Description
DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the /tmpfs/config_backup.bin resource.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37157
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Todor Donev
Affected Vendor
DBPower
View all reports →