CVE-2018-10770: Annigroup 5 In 1 Xvr Firmware

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

download.rsp on ShenZhen Anni "5 in 1 XVR" devices allows remote attackers to download the configuration (without a login) to discover the password.

Affected products

  • Annigroup 5 In 1 Xvr Firmware: affected versions not specified

Published 2018-05-09. Last modified 2026-06-17.