CVE-2020-24219 EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 23.6% (pctl 98)
Patch early
A public exploit exists.
Description
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve any file from the device's file system, including the configuration file with the cleartext administrative password.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 23.64% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-10-06 |
| Last modified | 2026-06-17 |
Affected (40)
| Vendor | Product |
|---|---|
| szuray | iptv\/h.264 video encoder firmware |
| szuray | uaioe264-1u |
| szuray | uce264-1-mini |
| szuray | uce264-1wb-mini |
| szuray | uce264-4-1u |
| szuray | uce264-8-1u |
| szuray | uhae264-16 |
| szuray | uhce264-1 |
| szuray | uhce264-16p32 |
| szuray | uhce264-1p2 |
| szuray | uhce264-1p2-1u |
| szuray | uhce264-1s |
| szuray | uhce264-1w |
| szuray | uhce264-1ws |
| szuray | uhce264-4p8 |
| szuray | uhe264-1-4k |
| szuray | uhe264-16 |
| szuray | uhe264-16l-3u |
| szuray | uhe264-16s-2u |
| szuray | uhe264-1l |
| szuray | uhe264-1l-4k |
| szuray | uhe264-1lw |
| szuray | uhe264-1s |
| szuray | uhe264-1s-mini |
| szuray | uhe264-1w-mini |
| szuray | uhe264-1wb-4g |
| szuray | uhe264-1wb-mini |
| szuray | uhe264-1wbs-2b |
| szuray | uhe264-1wbs-mini |
| szuray | uhe264-1ws-mini |
| szuray | uhe264-2-1u |
| szuray | uhe264-4 |
| szuray | uhe264-4-1u |
| szuray | uhe264-4l-1u |
| szuray | uhe264-8 |
| szuray | uhe264-8-1u |
| szuray | uhe264-8l-3u |
| szuray | uhe264-8s-2u |
| szuray | use264-16-3u |
| szuray | use264-1l |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal | 2020-10-19 |
References
- http://packetstormsecurity.com/files/159595/HiSilicon-Video-Encoder-1.97-File-Disclosure-Path-Traversal.html
- https://kojenov.com/2020-09-15-hisilicon-encoder-vulnerabilities/
- https://www.kb.cert.org/vuls/id/896979
- http://packetstormsecurity.com/files/159595/HiSilicon-Video-Encoder-1.97-File-Disclosure-Path-Traversal.html
- https://kojenov.com/2020-09-15-hisilicon-encoder-vulnerabilities/
- https://www.kb.cert.org/vuls/id/896979
→ the Explorer · watch your stack · NVD