CVE-2026-19828 | 648540858 wvp-GB28181-pro 2.7.4-20260107 Snapshot Endpoint PlayController.java deviceId/channelId path traversal (Issue 2175)

SecurityVulns

A vulnerability was found in 648540858 wvp-GB28181-pro 2.7.4-20260107. It has been rated as critical. This affects an unknown part of the file PlayController.java of the component Snapshot Endpoint. The manipulation of the argument deviceId/channelId leads to path traversal.

This vulnerability is listed as CVE-2026-19828. The attack may be initiated remotely. In addition, an exploit is available.VulDB Recent EntriesRead More