Executive brief
Vatilon-based IP cameras, commonly used for security and surveillance, contain a flaw that allows unauthorized individuals to view internal system files and directories. By accessing these restricted areas, an attacker can gather sensitive information about the camera's internal configuration and software structure. This information can be used to facilitate more advanced attacks, such as bypassing security logins or gaining full control over the device.
Technical details
A directory traversal and incorrect access control vulnerability exists in the embedded web server of Vatilon-based IP cameras (specifically observed in JIENUO PA4 models). The web server fails to properly restrict access to top-level directories such as /cgi-bin/, /view/, and /onvif/, and often has directory indexing enabled. An unauthenticated remote attacker can exploit this to browse internal scripts, HTML files, and JavaScript components. These exposed files contain sensitive implementation details, including internal API endpoints, request parameters, and in some cases, hardcoded credential fields within client-side logic. This exposure significantly lowers the barrier for secondary attacks like authentication bypass or unauthorized configuration changes via web.cgi.
Affected products
- Vatilon PA4 Firmware 1.12.37-20240124
Timeline
- 2025-01-02: disclosed: Initial CVE publication date
- 2026-01-02: advisory: NVD publication date