CVE-2019-25240: Rifatron Co., Ltd Dvr

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.

Affected products

Published 2025-12-24. Last modified 2026-06-17.