1 results (0.003 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

22 Oct 2024 — Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via login attempts. This can lead to the enumeration of user accounts and potentially facilitate other attacks, such as brute-forcing of passwords. The vulnerability arises from the application responding differently to login attempts with valid and invalid usernames. • https://github.com/rosembergpro/CVE-2024-48644 • CWE-203: Observable Discrepancy •