← volver
CVE-2021-4468

PLANEX CS-QP50F-ING2 Smart Camera Remote Configuration Disclosure

CVSS 8.7 HIGHEPSS 0.6%CWE-306
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.7EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
14 nov 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authentication. A remote, unauthenticated attacker can directly retrieve a compressed configuration backup file from the device. The backup contains sensitive configuration information, including credentials, allowing an attacker to obtain administrative access to the camera and compromise the confidentiality of the monitored environment.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →