CVE-2019-25236 describes an unauthenticated vulnerability in the iSeeQ Hybrid DVR WH-H4 1.03R, specifically within the get_jpeg script, allowing unauthorized access to live video streams. This critical vulnerability (CVSS 9.8) enables attackers to retrieve video snapshots from any camera channel by sending unauthenticated requests to the /cgi-bin/get_jpeg endpoint. The attack requires no user interaction or privileges, and its impact is high across confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 92/100 indicates significant potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ISeeQ | Hybrid DVR WH-H4 | 1.03R, 2.0.0.PCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.