CVE-2024-13894 Details
Description
Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to path traversal. When an affected device is connected to a mobile app, it opens a port 10000 enabling a user to download pictures shot at specific moments by providing paths to the files. However, the directories to which a user has access are not limited, allowing for path traversal attacks and downloading sensitive information. The vendor has not replied to reports, so the patching status remains unknown. Newer firmware versions might be vulnerable as well.
A path traversal vulnerability has been identified in Smartwares cameras CIP-37210AT and C724IP, as well as other models sharing the same firmware, all through version 3.3.0. When an affected device is connected to a mobile app, it opens port 10000, allowing users to download photos by specifying file paths. However, the lack of directory access restrictions enables path traversal attacks, potentially leading to the download of sensitive information. The vendor has not responded to reports, leaving the patching status unclear, and newer firmware versions may also be vulnerable.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 6, 2025CISA-ADP
Assessed Mar 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/en/posts/2025/03/CVE-2024-13892/ | [email protected] | AdvisoryBundleRemedy |
| https://www.smartwares.eu/en-gb/smartwares-cip-37210at-indoor-wi-fi-camera-cip--37210at | [email protected] | Broken LinkProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Smartwares CIP-37210AT | All versions |
CPE
Remediation
| |
| Smartwares C724IP | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 6, 2025 | New CVE Received | [email protected] |
Volerion