Lucene search

K

Szuray Security Vulnerabilities

cve
cve

CVE-2020-24214

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application crash. The device will not be able to perform its main purpose of video encoding and streaming for ...

9.8CVSS

9.5AI Score

0.022EPSS

2020-10-06 01:15 PM
66
2
cve
cve

CVE-2020-24215

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the device including retrieving the device's configuration (with the cleartext admin password), and uplo...

9.8CVSS

9.7AI Score

0.03EPSS

2020-10-06 01:15 PM
48
4
cve
cve

CVE-2020-24216

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrator configures a secret URL for RTSP streaming, the stream is still available via its default name such as /0. Unauthenticated attackers can view video streams that are meant to be ...

7.5CVSS

7.8AI Score

0.002EPSS

2020-10-06 02:15 PM
24
2
cve
cve

CVE-2020-24217

An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP request to upload a custom firmware component, possibly in conjunction with command injection, to a...

9.8CVSS

9.8AI Score

0.033EPSS

2020-10-06 02:15 PM
69
1
cve
cve

CVE-2020-24218

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in the executable file.

9.8CVSS

9.5AI Score

0.003EPSS

2020-10-06 02:15 PM
23
2
cve
cve

CVE-2020-24219

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the...

7.5CVSS

7.6AI Score

0.277EPSS

2020-10-06 02:15 PM
52
3