Junglewise Threat Intelligence

CVE-2026-18192: Vacron VIN-DS783E-E6 path traversal arbitrary file read

CVE-2026-18192 · Severity: medium · CVSS 6.5 · Published 2026-07-29

Executive brief

The Vacron VIN-DS783E-E6, a digital video recording or surveillance device, contains a security flaw that allows authorized users to access sensitive system files they should not be able to see. By exploiting this vulnerability, a remote attacker with basic login credentials can download internal configuration or system files, potentially leading to the exposure of sensitive operational data or further system compromise.

Technical details

A relative path traversal vulnerability (CWE-23) exists in the Vacron VIN-DS783E-E6 surveillance device. The flaw allows a remote attacker who has successfully authenticated with low-level privileges to bypass directory restrictions. By submitting specially crafted requests containing path traversal sequences (e.g., ../), an attacker can read and download arbitrary files from the underlying operating system. This can result in the disclosure of sensitive configuration data, credentials, or system logs. All versions of the product are currently reported as affected.

Affected products

  • Vacron VIN-DS783E-E6 All versions

Timeline

  • 2026-07-29: disclosed: Initial disclosure by TWCERT/CC and NVD publication

References

Related threats