Junglewise Threat Intelligence

CVE-2026-18191: Vacron VIN-DS783E-E6 hidden functionality credential disclosure

CVE-2026-18191 · Severity: critical · CVSS 9.8 · Published 2026-07-29

Executive brief

The Vacron VIN-DS783E-E6, a digital video recording or surveillance device, contains a hidden function that can be accessed by unauthorized users. An attacker can exploit this hidden feature over the network to steal the administrator's login credentials. This allows a remote attacker to take full control of the device, potentially viewing private video feeds or disabling security monitoring.

Technical details

The Vacron VIN-DS783E-E6 surveillance device is vulnerable to a 'Hidden Functionality' flaw (CWE-912). An unauthenticated attacker can remotely access a specific undocumented or hidden function within the device's firmware or web interface. By interacting with this function, the attacker can retrieve the administrator credentials in plain text or bypass authentication to gain full administrative access. This vulnerability is reachable via the network without any user interaction, posing a significant risk of complete device compromise. All versions of the product are currently reported as affected.

Affected products

  • Vacron VIN-DS783E-E6 All versions

Timeline

  • 2026-07-29: disclosed: Initial disclosure by TWCERT/CC
  • 2026-07-29: advisory: NVD record published

References

Related threats