Back

HIGH

JVC VN-T IP-Camera Directory Traversal via check.cgi

Published Nov 12, 2025

Description

JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote attacker can leverage this vulnerability to read arbitrary files on the device.

Affected products

Remediation

Vendor solution

The VN-T216VPRU product page has been archived and appears to no longer be supported by the vendor. Additionally, all VN-T series cameras appear to share the same firmware.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Nov 12, 2025
Updated Apr 7, 2026
Reserved Nov 6, 2025
CISA Vulnrichment
Updated Nov 13, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a