Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers to access sensitive information.
References
Link | Resource |
---|---|
https://docs.biltema.com/v2/documents/file/nb/6a9ff001-a0e0-48c4-a802-83e8b5a5e213 | Vendor Advisory |
https://kth.diva-portal.org/smash/get/diva2:1729289/FULLTEXT01.pdf | Vendor Advisory |
https://docs.biltema.com/v2/documents/file/nb/6a9ff001-a0e0-48c4-a802-83e8b5a5e213 | Vendor Advisory |
https://kth.diva-portal.org/smash/get/diva2:1729289/FULLTEXT01.pdf | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-02-03 15:15
Updated : 2025-03-26 18:15
NVD link : CVE-2022-34138
Mitre link : CVE-2022-34138
CVE.ORG link : CVE-2022-34138
JSON object : View
Products Affected
biltema
- ip_camera_firmware
- ip_camera
- baby_camera_firmware
- baby_camera
CWE
CWE-639
Authorization Bypass Through User-Controlled Key