PT-2026-6824 · Dbpower · Dbpower C300 Hd Camera

·

CVE-2020-37157

·

Published

2026-02-06

·

Updated

2026-02-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DBPower C300 HD Camera (affected versions not specified)
Description The DBPower C300 HD Camera has a configuration disclosure issue. Unauthenticated attackers can obtain sensitive credentials by accessing an unprotected configuration backup endpoint. Specifically, attackers can download the configuration file and extract hardcoded username and password from the /tmpfs/config backup.bin resource.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-37157

Affected Products

Dbpower C300 Hd Camera