peter bassill · operator
$ cve CVE-2020-24219 JSON

CVE-2020-24219 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 23.6% (pctl 98)

Patch early

A public exploit exists.

Description

An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS23.64% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2020-10-06
Last modified2026-06-17

Affected (40)

VendorProduct
szurayiptv\/h.264 video encoder firmware
szurayuaioe264-1u
szurayuce264-1-mini
szurayuce264-1wb-mini
szurayuce264-4-1u
szurayuce264-8-1u
szurayuhae264-16
szurayuhce264-1
szurayuhce264-16p32
szurayuhce264-1p2
szurayuhce264-1p2-1u
szurayuhce264-1s
szurayuhce264-1w
szurayuhce264-1ws
szurayuhce264-4p8
szurayuhe264-1-4k
szurayuhe264-16
szurayuhe264-16l-3u
szurayuhe264-16s-2u
szurayuhe264-1l
szurayuhe264-1l-4k
szurayuhe264-1lw
szurayuhe264-1s
szurayuhe264-1s-mini
szurayuhe264-1w-mini
szurayuhe264-1wb-4g
szurayuhe264-1wb-mini
szurayuhe264-1wbs-2b
szurayuhe264-1wbs-mini
szurayuhe264-1ws-mini
szurayuhe264-2-1u
szurayuhe264-4
szurayuhe264-4-1u
szurayuhe264-4l-1u
szurayuhe264-8
szurayuhe264-8-1u
szurayuhe264-8l-3u
szurayuhe264-8s-2u
szurayuse264-16-3u
szurayuse264-1l

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD