PT-2026-72020 · Unknown · Wvp Gb28181 Pro

·

CVE-2026-19828

·

Published

2026-08-14

·

Updated

2026-08-18

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions wvp-GB28181-pro version 2.7.4-20260107
Description A path traversal issue exists in the Snapshot Endpoint component within the PlayController.java file. A remote attacker can exploit this by manipulating the deviceId or channelId arguments, allowing unauthorized access to files or directories on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19828

Affected Products

Wvp Gb28181 Pro