CVE-2022-30620
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.
MISC: https://www.gov.il/en/departments/faq/cve_advisories
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30620
published: 18. 7. 2022