Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-06 16:15
Updated : 2026-01-08 18:09
NVD link : CVE-2020-36925
Mitre link : CVE-2020-36925
CVE.ORG link : CVE-2020-36925
JSON object : View
Products Affected
No product.
CWE
CWE-331
Insufficient Entropy
