Security Advisory

CVE-2016-15055

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-11-12 22:08:35
Last updated 2026-04-07 14:03:33
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.