PT-2025-53322 · Iseeq · Hybrid Dvr Wh-H4

Published

2025-12-24

·

Updated

2025-12-24

·

CVE-2019-25236

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get jpeg script that allows unauthorized access to live video streams. Attackers can retrieve video snapshots from specific camera channels by sending requests to the /cgi-bin/get jpeg endpoint without authentication.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2019-25236

Affected Products

Hybrid Dvr Wh-H4