PT-2026-6824 · Dbpower · Dbpower C300 Hd Camera

Todor Donev

·

Published

2026-02-06

·

Updated

2026-02-07

·

CVE-2020-37157

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DBPower C300 HD Camera (affected versions not specified)
Description The DBPower C300 HD Camera has a configuration disclosure issue. Unauthenticated attackers can obtain sensitive credentials by accessing an unprotected configuration backup endpoint. Specifically, attackers can download the configuration file and extract hardcoded username and password from the /tmpfs/config backup.bin resource.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2020-37157

Affected Products

Dbpower C300 Hd Camera