Description
Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file path and read corresponding files located on the server. The issue was fixed in version 2026-04-23 of the KG-5260xxxx-IL-(G)2 cameras. Rest of the products were fixed in version 2025-04-21.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version before 2025-04-21
Any version before 2025-04-21
Any version before 2025-04-21
Any version before 2025-04-21
Any version before 2025-04-21
Any version before 2025-04-21
Any version before 2025-04-21
Any version before 2026-04-23
Credits
Łukasz Bawolski (Exea Data Center)
References
cert.pl/posts/2026/05/CVE-2026-7766