CVE-2020-24219 is a path traversal vulnerability affecting URayTech IPTV/H.264/H.265 video encoders up to version 1.97. This flaw allows unauthenticated attackers to retrieve arbitrary files, including configuration files containing cleartext administrative passwords, from the device's file system. With a CVSS score of 7.5 (High), the vulnerability is easily exploitable over the network without user interaction, leading to high confidentiality impact. While not listed in CISA KEV, an ExploitDB entry confirms public exploit code availability, though community discussion and media coverage remain low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.97CPE matchmatch criteria | cpe:2.3:o:szuray:iptv\/h.264_video_encoder_firmware:*:*:*:*:*:*:*:* | ||
<= 1.97CPE matchmatch criteria | cpe:2.3:o:szuray:iptv\/h.265_video_encoder_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.