CVE-2022-30620

On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.

MISC: https://www.gov.il/en/departments/faq/cve_advisories
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-30620

14 years
257 countries
687k users
4547k calculations
Logo www.eleksys.cz
Logo www.elsec.cz
Logo www.cctvforum.com
Logo ipcamtalk.com
Logo sectech.co.nz
Logo www.a1securitycameras.com