Loading
CeNova, Night OWL, Novo, Pulnix, QSee, Securus, and TBK Vision DVR devices allow remote attackers to download a file and obtain sensitive credential information via a direct request for the download.rsp URI.
Use Tbkvision vendor hub and Tbk-Dvr4216 Firmware product page to widen CVE-2018-10676 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-9995 for nearby disclosures in the same product family.