PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authentication. A remote, unauthenticated attacker can directly retrieve a compressed configuration backup file from the device. The backup contains sensitive configuration information, including credentials, allowing an attacker to obtain administrative access to the camera and compromise the confidentiality of the monitored environment.
History

Mon, 17 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 16 Nov 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Planex cs-qp50f
CPEs cpe:2.3:h:planex:cs-qp50f:-:*:*:*:*:*:*:*
Vendors & Products Planex cs-qp50f

Sat, 15 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Planex
Planex cs-qp50f-ing2
Vendors & Products Planex
Planex cs-qp50f-ing2

Fri, 14 Nov 2025 23:00:00 +0000

Type Values Removed Values Added
Description PLANEX CS-QP50F-ING2 smart cameras expose a configuration backup interface over HTTP that does not require authentication. A remote, unauthenticated attacker can directly retrieve a compressed configuration backup file from the device. The backup contains sensitive configuration information, including credentials, allowing an attacker to obtain administrative access to the camera and compromise the confidentiality of the monitored environment.
Title PLANEX CS-QP50F-ING2 Smart Camera Remote Configuration Disclosure
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-11-14T22:52:05.351Z

Updated: 2025-11-17T20:37:28.498Z

Reserved: 2025-11-14T20:29:56.062Z

Link: CVE-2021-4468

cve-icon Vulnrichment

Updated: 2025-11-17T20:37:25.925Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-14T23:15:42.730

Modified: 2025-11-18T14:06:55.963

Link: CVE-2021-4468

cve-icon Redhat

No data.