CVE-2004-2507 describes an absolute path traversal vulnerability in the main.cgi script of the Linksys WVC11B Wireless-B Internet Video Camera. This flaw allows unauthenticated remote attackers to read arbitrary files on the device by manipulating the 'next_file' parameter with an absolute pathname. With a CVSS score of 5.0, this vulnerability presents a low-complexity attack vector (AV:N/AC:L/Au:N) that could lead to information disclosure (C:P) without affecting integrity or availability. While not listed on the KEV catalog and showing no active exploitation or community discussion, an exploit module for file disclosure exists on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.10CPE matchmatch criteria | cpe:2.3:h:linksys:wvc11b:2.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.