CVE-2020-37157 PUBLISHED

DBPower C300 HD Camera - Remote Configuration Disclosure

Assigner: VulnCheck
Reserved: 03.02.2026 Published: 06.02.2026 Updated: 06.02.2026

DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the /tmpfs/config_backup.bin resource.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor DBPower
Product DBPower C300 HD Camera
Versions
  • Version - is affected

Credits

  • Todor Donev finder

References

Problem Types

  • Missing Authentication for Critical Function CWE