Genie Access · Genie Access Wip3Bvaf Wish Ip 3Mp Ir Auto Focus Bullet Camera · CVE-2019-7315
**Name of the Vulnerable Software and Affected Versions**
Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera versions prior to 4.x
**Description**
The issue allows directory traversal via the web interface, as demonstrated by reading /etc/shadow. This product is discontinued, and its final firmware version has this issue.
**Recommendations**
For Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera versions prior to 4.x, consider restricting access to the web interface until a resolution is available. As a temporary workaround, avoid using the web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.