Description
iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized access to live video streams. Attackers can retrieve video snapshots from specific camera channels by sending requests to the /cgi-bin/get_jpeg endpoint without authentication.
Problem types
Missing Authentication for Critical Function
Product status
2.0.0.P
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5539.php
www.exploit-db.com/exploits/47562 (ExploitDB-47562)
www.iseeq.co.kr (iSeeQ Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5539.php (Zero Science Lab Disclosure (ZSL-2019-5539))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.