Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Neom22

#35871of 53,622
7.5Total CVSS
Vulnerabilities · 1
PT-2020-7877
7.5
2020-02-18
Bosch Security Systems · Nbn-498 Dinion2X Day/Night Ip Cameras · CVE-2015-6970
Name of the Vulnerable Software and Affected Versions: Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware version 4.54.0026 Description: The issue allows remote attackers to conduct XML injection attacks. This is achieved via the `idstring` parameter to the "rcp.xml" endpoint. Recommendations: For Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware version 4.54.0026, avoid using the `idstring` parameter in the "rcp.xml" endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the "rcp.xml" endpoint to minimize the risk of exploitation.