peter bassill · operator
$ cve CVE-2013-1391 JSON

CVE-2013-1391 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 76.1% (pctl 100)

Patch early

A public exploit exists.

Description

Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS76.11% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2019-10-30
Last modified2026-06-16

Affected (40)

VendorProduct
capturecctvcdr 0410ve
capturecctvcdr 0410ve firmware
capturecctvcdr 0820vde
capturecctvcdr 0820vde firmware
hachihv-04rd pro
hachihv-04rd pro firmware
hachihv-08rd pro
hachihv-08rd pro firmware
huntcctvdr6-704a4h
huntcctvdr6-704a4h firmware
huntcctvdr6-708a4h
huntcctvdr6-708a4h firmware
huntcctvdr6-7316a4h
huntcctvdr6-7316a4h firmware
huntcctvdr6-7316a4hl
huntcctvdr6-7316a4hl firmware
huntcctvdvr-04ch
huntcctvdvr-04ch firmware
huntcctvdvr-04nc
huntcctvdvr-04nc firmware
huntcctvdvr-08ch
huntcctvdvr-08ch firmware
huntcctvdvr-08nc
huntcctvdvr-08nc firmware
huntcctvdvr-16ch
huntcctvdvr-16ch firmware
huntcctvhdr-04kd
huntcctvhdr-04kd firmware
huntcctvhdr-08kd
huntcctvhdr-08kd firmware
novuscctvnv-dvr1204
novuscctvnv-dvr1204 firmware
novuscctvnv-dvr1208
novuscctvnv-dvr1208 firmware
novuscctvnv-dvr1216
novuscctvnv-dvr1216 firmware
vsptw-dvr604
vsptw-dvr604 firmware
vsptw-dvr616
vsptw-dvr616 firmware

Public exploits

SourceTitleDate
exploit-dbMultiple Hunt CCTV - Information Disclosure2013-01-29

References

→ the Explorer  ·  watch your stack  ·  NVD