CVE-2020-37157: DBPower C300 HD Camera - Remote Configuration Disclosure
DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the /tmpfs/configbackup.bin resource.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37157?
CVE-2020-37157 has a medium severity level due to the risk of sensitive credential exposure.
How do I fix CVE-2020-37157?
To fix CVE-2020-37157, ensure that the configuration backup endpoint is secured and requires authentication.
What type of vulnerability is CVE-2020-37157?
CVE-2020-37157 is a remote configuration disclosure vulnerability.
Who is affected by CVE-2020-37157?
CVE-2020-37157 affects users of the DBPower C300 HD Camera.
Can CVE-2020-37157 lead to further exploitation?
Yes, unauthorized access to sensitive credentials from CVE-2020-37157 may lead to further exploitation of the affected device.