Junglewise Threat Intelligence

CVE-2026-7766: Kenik Camera management panel path traversal

CVE-2026-7766 · Severity: info · CVSS 8.3 · Published 2026-05-25

Executive brief

The management panel for Kenik security cameras contains a flaw that allows unauthorized individuals to access sensitive system files. By sending a specially crafted web request, an attacker can bypass security restrictions to read internal configuration or system data. This could lead to the exposure of credentials or other private information stored on the camera hardware.

Technical details

A path traversal vulnerability (CWE-22) exists in the web-based management interface of several Kenik camera models. The root cause is improper validation of user-supplied file paths in GET requests, allowing an unauthenticated attacker to navigate outside the intended web root directory. By exploiting this, an attacker can retrieve sensitive system files. The vulnerability is reachable over the network (typically adjacent network as per CVSS) without any prior authentication. Patches have been released for all affected models, with specific firmware versions 2026-04-23 and 2025-04-21 addressing the issue depending on the hardware series.

Affected products

  • Kenik KG-5230TAS-IL-3 before 2025-04-21
  • Kenik KG-5230TAS-IL-G3 before 2025-04-21
  • Kenik KG-5230DAS-IL-G3 before 2025-04-21
  • Kenik KG-5260TZAS-IL-3 before 2025-04-21
  • Kenik KG-5260DZAS-IL-3 before 2025-04-21
  • Kenik KG-5260TZAS-IL-G3 before 2025-04-21
  • Kenik KG-5260DZAS-IL-G3 before 2025-04-21
  • Kenik KG-5260xxxx-IL-(G)2 before 2026-04-23

Timeline

  • 2026-05-25: disclosed: Initial disclosure by CERT.PL
  • 2025-04-21: patched: Patch released for most models
  • 2026-04-23: patched: Patch released for KG-5260xxxx-IL-(G)2 series

References