DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the /tmpfs/config_backup.bin resource.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Feb 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessing the /tmpfs/config_backup.bin resource. | |
| Title | DBPower C300 HD Camera - Remote Configuration Disclosure | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-06T23:14:09.598Z
Reserved: 2026-02-03T16:27:45.310Z
Link: CVE-2020-37157
No data.
Status : Received
Published: 2026-02-07T00:15:55.760
Modified: 2026-02-07T00:15:55.760
Link: CVE-2020-37157
No data.
OpenCVE Enrichment
No data.