CVE-2025-1739

An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vulnerability allows an attacker to retrieve administrator's credentials in cleartext by sending a request against the server using curl with random credentials to "/en/player/activex_pal.asp" and successfully authenticating the application.
Configurations

No configuration.

History

27 Feb 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-27 13:15

Updated : 2025-02-27 13:15


NVD link : CVE-2025-1739

Mitre link : CVE-2025-1739

CVE.ORG link : CVE-2025-1739


JSON object : View

Products Affected

No product.

CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel