VYPR
High severity8.2NVD Advisory· Published Jul 18, 2022· Updated Jun 17, 2026

CVE-2022-30620

CVE-2022-30620

Description

On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.

Affected products

4
  • cpe:2.3:o:cellinx:cellinx_nvt_-_ip_ptz_camera_firmware:3.2.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:cellinx:cellinx_nvt_-_ip_ptz_camera_firmware:3.2.0:*:*:*:*:*:*:*
    • cpe:2.3:o:cellinx:cellinx_nvt_-_ip_ptz_camera_firmware:3.2.1:*:*:*:*:*:*:*
  • Cellinx/Camerallm-create
  • Cellinx/Cellinx NVT - IP PTZ Camerav5
    Range: 3.2.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.