Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the driving recorder through ftp and other protocols.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://github.com/Question-h/vuln/blob/master/70mai_a500s_backdoor.md | third party advisory exploit |
https://github.com/Question-h/vuln/blob/master/CVE-2023-43271.md | third party advisory |