Security Advisory

CVE-2020-36925

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-06 15:52:28
Last updated 2026-01-06 16:51:48
Assigner VulnCheck
State PUBLISHED

Description

Arteco Web Client DVR/NVR contains a session hijacking vulnerability with insufficient session ID complexity that allows remote attackers to bypass authentication. Attackers can brute force session IDs within a specific numeric range to obtain valid sessions and access live camera streams without authorization.