Executive brief
The Vacron VIN-DS783E-E6, a digital video recording or surveillance device, contains a hidden function that can be accessed by unauthorized users. An attacker can exploit this hidden feature over the network to steal the administrator's login credentials. This allows a remote attacker to take full control of the device, potentially viewing private video feeds or disabling security monitoring.
Technical details
The Vacron VIN-DS783E-E6 surveillance device is vulnerable to a 'Hidden Functionality' flaw (CWE-912). An unauthenticated attacker can remotely access a specific undocumented or hidden function within the device's firmware or web interface. By interacting with this function, the attacker can retrieve the administrator credentials in plain text or bypass authentication to gain full administrative access. This vulnerability is reachable via the network without any user interaction, posing a significant risk of complete device compromise. All versions of the product are currently reported as affected.
Affected products
- Vacron VIN-DS783E-E6 All versions
Timeline
- 2026-07-29: disclosed: Initial disclosure by TWCERT/CC
- 2026-07-29: advisory: NVD record published