Executive brief
A security vulnerability has been identified in the web management interface of WTI camera control systems. This flaw allows an unauthorized person to bypass security restrictions and view sensitive files stored on the device, such as system passwords and configuration data. An attacker could use this information to gain full control over the device or access other parts of the corporate network.
Technical details
A path traversal vulnerability (CWE-22) exists in the WTI Camera Control web management interface due to insufficient sanitization of user-supplied input in HTTP request paths. An unauthenticated remote attacker can use directory traversal sequences (e.g., '../../') to escape the web root and read arbitrary files from the underlying Linux filesystem, such as /etc/passwd or configuration files containing credentials. The vulnerability is exploitable via a simple network request without any prior authentication or user interaction. Successful exploitation provides a foundation for privilege escalation or lateral movement within the network using recovered credentials.
Affected products
- Wireless Technology, Inc. (WTI) Camera Control Web Management Interface 3.5.0.r (build 2024/05/24)
Timeline
- 2025-12-29: other: Vulnerability discovered
- 2026-02-04: other: CVE assigned by MITRE
- 2026-07-10: advisory: NVD publication date