S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-15745 Scanner

CVE-2018-15745 scanner - Directory Traversal vulnerability in Argus Surveillance DVR

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-15745
7.5
CVSS

Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Argus Surveillance DVR is a security camera device that allows users to monitor and record activity in their homes, offices and other locations. The system offers remote access, real-time alerts, motion detection, and many other security features. The device is designed to help individuals and organizations monitor their premises, detect intrusions, and prevent theft or other crimes. 

One vulnerability that has been discovered in Argus Surveillance DVR is CVE-2018-15745. This vulnerability allows hackers to access files on the device without proper authentication. The vulnerability is caused by an unauthenticated directory traversal that can be triggered by entering "..%2F" into the WEBACCOUNT.CGI RESULTPAGE parameter. 

Exploiting this vulnerability can lead to the disclosure of sensitive information, such as user data, camera footage, and other files stored on the device. This information can be used by attackers to carry out other malicious activities, including identity theft, cyber espionage or fraud. The vulnerability can also compromise the overall security of the device and make it more vulnerable to other types of attacks.

In conclusion, it is essential for individuals and organizations to be aware of the potential vulnerabilities in their digital assets, such as the Argus Surveillance DVR device. By taking proactive measures to secure these devices and staying informed about potential threats, users can help prevent security breaches and protect sensitive information. The s4e.io platform offers pro features for detecting vulnerabilities in digital assets, allowing users to stay informed and take necessary actions to prevent cyberattacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is important to take the following precautionary measures:

  • Update the device firmware to the latest version.
  • Disable remote access to the device.
  • Change default usernames and passwords.
  • Limit access to the device to authorized personnel only.
  • Implement additional security measures, such as firewalls, intrusion detection, and antivirus software.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.