Description
Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access to live video streams. Attackers can exploit the Mobile Web Viewer module by specifying channel numbers to retrieve sequential video snapshots without authentication.
Problem types
Missing Authentication for Critical Function
Product status
7brid DVR (HD3-16V2, DX3-16V2/08V2/04V2, MX3-08V2/04V2)
Firmware: <=8.0 (000143)
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5532.php
www.exploit-db.com/exploits/47368
www.exploit-db.com/exploits/47368 (ExploitDB-47368)
www.rifatron.com (Rifatron Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5532.php (Zero Science Lab Disclosure (ZSL-2019-5532))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.