Vulnerability Details CVE-2018-10676
CeNova, Night OWL, Novo, Pulnix, QSee, Securus, and TBK Vision DVR devices allow remote attackers to download a file and obtain sensitive credential information via a direct request for the download.rsp URI.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
Products affected by CVE-2018-10676
-
cpe:2.3:h:tbkvision:tbk-dvr4104:-
-
cpe:2.3:h:tbkvision:tbk-dvr4216:-
-
cpe:2.3:o:tbkvision:tbk-dvr4104_firmware:-
-
cpe:2.3:o:tbkvision:tbk-dvr4216_firmware:-