Vulnerability Details CVE-2018-14064
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.748
EPSS Ranking 98.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 5.0
Products affected by CVE-2018-14064
-
cpe:2.3:h:velotismart_project:velotismart_wifi:-
-
cpe:2.3:o:velotismart_project:velotismart_wifi_firmware:b-380