PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authentication. A remote, unauthenticated attacker can directly retrieve a compressed configuration backup file from the device. The backup contains sensitive configuration information, including credentials, allowing an attacker to obtain administrative access to the camera and compromise the confidentiality of the monitored environment.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 16 Nov 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Planex cs-qp50f
|
|
| CPEs | cpe:2.3:h:planex:cs-qp50f:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Planex cs-qp50f
|
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Planex
Planex cs-qp50f-ing2 |
|
| Vendors & Products |
Planex
Planex cs-qp50f-ing2 |
Fri, 14 Nov 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authentication. A remote, unauthenticated attacker can directly retrieve a compressed configuration backup file from the device. The backup contains sensitive configuration information, including credentials, allowing an attacker to obtain administrative access to the camera and compromise the confidentiality of the monitored environment. | |
| Title | PLANEX CS-QP50F-ING2 Smart Camera Remote Configuration Disclosure | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-11-14T22:52:05.351Z
Updated: 2025-11-17T20:37:28.498Z
Reserved: 2025-11-14T20:29:56.062Z
Link: CVE-2021-4468
Updated: 2025-11-17T20:37:25.925Z
Status : Awaiting Analysis
Published: 2025-11-14T23:15:42.730
Modified: 2025-11-18T14:06:55.963
Link: CVE-2021-4468
No data.