Executive brief
C-MOR Video Surveillance is a surveillance system used to record and manage video feeds from networked cameras. An unauthenticated attacker can exploit a path traversal vulnerability in the web interface to read arbitrary files from the underlying operating system, potentially exposing sensitive configuration data, credentials, and system information that could facilitate further attacks.
Technical details
The vulnerability is a path traversal (directory traversal) flaw in the show-movies.pml component of C-MOR Video Surveillance. The 'cam' parameter is concatenated directly into a file system path without validation or sanitization of directory traversal sequences (../ or URL-encoded %2f). An unauthenticated attacker on the network can craft HTTP requests containing traversal payloads to navigate outside the intended camera recording directory and access arbitrary files readable by the web server process, such as /etc/passwd, configuration files, and logs. No authentication is required; the exploit is network-accessible and can be automated. Fixes or patched versions have not been confirmed in the advisory text.
Affected products
- za-internet GmbH C-MOR Video Surveillance up to 6.0104
Timeline
- 2026-07-23: disclosed: Advisory published by Alb Cyber Guards
- 2026-09-15: advisory: CVE-2026-51134 registered in NVD