CVE-2016-6536: Aver EH6108H+ Firmware

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

The /setup URI on AVer Information EH6108H+ devices with firmware X9.03.24.00.07l allows remote attackers to bypass intended page-access restrictions or modify passwords by leveraging knowledge of a handle parameter value.

Affected products

  • Aver EH6108H+ Firmware: up to and including x9.03.24.00.07l

Published 2016-09-19. Last modified 2026-06-17.