PT-2025-9925 · Smartwares · Smartwares Cameras
Marcin Wyczechowski
+2
·
Published
2025-03-06
·
Updated
2025-03-07
·
CVE-2024-13894
CVSS v4.0
5.9
Medium
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Smartwares cameras versions up to 3.3.0
Description
The issue allows for path traversal attacks, enabling access to sensitive information by manipulating file paths. When connected to a mobile app, affected devices open port 10000, allowing users to download pictures by providing specific file paths. However, the directories accessible to users are not properly restricted, facilitating the path traversal attacks. The vendor has not responded to reports, and the patching status is unknown.
Recommendations
For versions up to 3.3.0, as a temporary workaround, consider restricting access to port 10000 when not in use, to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smartwares Cameras