CVE-2020-37157: Dbpower c300 Hd Camera
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the /tmpfs/config_backup.bin resource.
Affected products
- Dbpower Dbpower c300 Hd Camera: affected versions not specified
Published 2026-02-07. Last modified 2026-06-17.