CVE-2024-13130: Dahua IPC-HFW1200S Web Interface Sha1Account1 path traversal
A vulnerability was found in Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z and IPC-HDW1200S up to 20241222. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ../mtd/Config/Sha1Account1 of the component Web Interface. The manipulation leads to path traversal: '../filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13130?
CVE-2024-13130 has been rated as problematic.
Which devices are affected by CVE-2024-13130?
CVE-2024-13130 affects Dahua IPC-HFW1200S, IPC-HFW2300R-Z, IPC-HFW5220E-Z, and IPC-HDW1200S up to version 20241222.
How do I fix CVE-2024-13130?
To address CVE-2024-13130, update the affected Dahua devices to the latest firmware version.
What functionality is affected by CVE-2024-13130?
CVE-2024-13130 impacts an unknown functionality of the file ../mtd/Config/Sha1Account1 within the web interface.
Is there a known exploit for CVE-2024-13130?
At this time, there is no publicly available information about a specific exploit for CVE-2024-13130.