Executive brief
A security vulnerability exists in the AVer PTC310UV2 professional tracking camera. An attacker can remotely access sensitive information, including the administrator's login credentials, which are stored in plain text on an unprotected web page. This could allow an unauthorized person to take full control of the camera, view its video feed, or change its settings.
Technical details
The AVer PTC310UV2 camera (firmware v0.1.0000.59) contains multiple vulnerabilities in its web interface. While the primary CVE description mentions remote code execution via the 'SendAction' function (CWE-77), associated research indicates a critical information disclosure flaw where the endpoint '/action?get=acc' exposes valid administrator credentials in plaintext. These vulnerabilities are reachable over the network without prior authentication. An attacker can leverage the exposed credentials or the command injection flaw to gain unauthorized access and execute arbitrary commands on the device. Users are advised to restrict network access to the camera's management interface.
Affected products
- AVer PTC310UV2 firmware 0.1.0000.59
Timeline
- 2025-07-30: advisory: Initial NVD publication date