Castel
Castel Nextgen DVR Firmware: vulnerabilities and CVEs
Castel Nextgen DVR Firmware has 4 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11682 | Medium (6.5) | 0.64% | — | Jun 4, 2020 | Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not… |
| CVE-2020-11681 | High (8.1) | 1.1% | — | Jun 4, 2020 | Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obtain the SMTP credentials. |
| CVE-2020-11680 | Medium (6.5) | 1.2% | — | Jun 4, 2020 | Castel NextGen DVR v1.0.0 is vulnerable to authorization bypass on all administrator functionality. The application fails to check that a request was submitted by an administrator. Consequently, a normal user can… |
| CVE-2020-11679 | High (8.8) | 2.0% | — | Jun 4, 2020 | Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionality. Adminstrator/Users/Edit/:UserId fails to check that the request was submitted by an… |