Description
Beward N100 H.264 VGA IP Camera M2.1.6 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft a malicious web page with a hidden form to add an admin user by tricking a logged-in user into submitting the form.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5510.php
www.exploit-db.com/exploits/46318 (ExploitDB-46318)
www.beward.net (Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5510.php (Zero Science Lab Disclosure (ZSL-2019-5510))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.