Executive brief
The Vacron VIN-DS783E-E6, a digital video recording or surveillance device, contains a security flaw that allows authorized users to access sensitive system files they should not be able to see. By exploiting this vulnerability, a remote attacker with basic login credentials can download internal configuration or system files, potentially leading to the exposure of sensitive operational data or further system compromise.
Technical details
A relative path traversal vulnerability (CWE-23) exists in the Vacron VIN-DS783E-E6 surveillance device. The flaw allows a remote attacker who has successfully authenticated with low-level privileges to bypass directory restrictions. By submitting specially crafted requests containing path traversal sequences (e.g., ../), an attacker can read and download arbitrary files from the underlying operating system. This can result in the disclosure of sensitive configuration data, credentials, or system logs. All versions of the product are currently reported as affected.
Affected products
- Vacron VIN-DS783E-E6 All versions
Timeline
- 2026-07-29: disclosed: Initial disclosure by TWCERT/CC and NVD publication