Executive brief
AVer PTC310UV2 professional tracking cameras contain a security flaw in their web management interface. The camera's login process incorrectly handles user credentials, allowing a remote attacker to intercept and view sensitive login information. This could lead to unauthorized access to the camera's video feed and management settings.
Technical details
The vulnerability is classified as an exposure of sensitive information (CWE-200) within the web-based management interface of AVer PTC310UV2 cameras. The root cause is a flawed authentication mechanism where the frontend makes a request to a specific endpoint ('Get=acc') that returns the device's username and password in plaintext to the client's browser for local validation. An attacker can exploit this by monitoring network traffic or crafting a request to the vulnerable endpoint, which returns credentials in a 'username&password&' format regardless of whether the user is already authenticated. This allows for full credential theft and subsequent administrative access to the device.
Affected products
- AVer PTC310UV2 firmware 0.1.0000.59
Timeline
- 2025-07-30: advisory: Initial NVD publication