Post

Hikvision Video Encoding Device Access Gateway Data Arbitrary File Reading

Hikvision Video Encoding Device Access Gateway Data Arbitrary File Reading

HIKVISION Video Encoding Device Access Gateway $DATA Any file reading

Vulnerability Description

HIKVISION Video encoding device access gateway has configuration error characteristics, and the special suffix requests the php file to read the source code.

Vulnerability Impact

HIKVISION Video Encoding Device Access Gateway

Network surveying and mapping

Vulnerability reappears

Login page

img

Verify POC

/data/login.php::$DATA

img

This post is licensed under CC BY 4.0 by the author.