CVE-2026-7766
Deferred
Deferred - Pending Action
Path Traversal in Kenik Camera Management Panel
Publication date: 2026-05-25
Last updated on: 2026-05-25
Assigner: CERT.PL
Description
Description
Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file path and read corresponding files located on the server.
The issue was fixed in version 2026-04-23 of the KG-5260xxxx-IL-(G)2 cameras.
Rest of the products were fixed in version 2025-04-21.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| kenik | kg-5260xxxx-il-(g)2 | 2026-04-23 |
| kenik | kg-5260xxxx-il-(g)2 | to 2026-04-23 (exc) |
| kenik | kg-5260xxxx-il-(g)2 | to 2025-04-21 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-22 | The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. |