S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-14064 Scanner

CVE-2018-14064 scanner - Directory Traversal vulnerability in VelotiSmart WiFi B-380

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
14
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-14064
9.8
CVSS

The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The VelotiSmart WiFi B-380 is a camera device that is commonly used for surveillance and monitoring purposes in homes, offices, and public spaces. This device comes equipped with the uc-http service 1.0.0, which is responsible for handling web traffic and communicating with the camera's operating system. While this service is vital for the device's operation, it has recently been found to contain a significant vulnerability - CVE-2018-14064.

This vulnerability allows for Directory Traversal, which means that an attacker can gain access to restricted directories on the device by manipulating the web traffic sent to the uc-http service. By using the "/../../etc/passwd" command on TCP port 80, an attacker can download the device's password file and gain access to sensitive information.

If this vulnerability is left unaddressed, it can lead to serious consequences for the security and privacy of the device and its users. Hackers can exploit this vulnerability to gain unauthorized access to the device, spy on its users, or even use it as a launchpad for further attacks on the network it is connected to. Furthermore, as the device is often used in public spaces, it can pose a significant threat to the safety and security of those being monitored.

By using the pro features of s4e.io, users can quickly and easily learn about vulnerabilities in their digital assets, including the VelotiSmart WiFi B-380 camera device. This platform provides detailed information on the latest security threats, as well as customized alerts and recommendations for protecting against them. So, stay up-to-date with your digital security and protect yourself against potential threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended that users take the following precautions:

  • Update the firmware of the device to the latest version, as it may contain patches for this vulnerability.
  • Use strong passwords for all accounts associated with the device, and change them regularly.
  • Restrict network access to the device by using a firewall and filtering incoming traffic.
  • Regularly monitor the device and network for any suspicious activity, and report it immediately.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.