关键信息 漏洞详情 受影响设备: Camera model PTC310UV2, firmware version 0.1.0000.59 漏洞位置: Web interface used to access the camera 发现方式: During a penetration test 描述 披露内容: Two vulnerabilities identified in AVer firmware login web interface CVE编号: CVE-2025-45619 (first of two vulnerabilities) 相关链接: Second vulnerability: CVE-2025-45620 具体问题 CVE-2025-45619: Open endpoints on the host exposing valid login credentials for the administrator user 示例URL: 暴露的凭证: 建议 存储方式: Credentials should not be stored on open endpoints or in plaintext 其他风险: Possible storage of other sensitive data on these endpoints 建议措施: Review and restrict access to these endpoints