CVE-2023-30466
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests on the targeted device. Successful exploitation of this vulnerability could allow remote attacker to account takeover on the targeted device.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 1.13%
- CWE
- CWE-640
- Published
- 2023-04-28
- Last modified
- 2026-03-13
Affected products
- Milesight NVR MS-Nxxxx-xxG
- Milesight NVR MS-Nxxxx-xxE
- Milesight NVR MS-Nxxxx-xxT
- Milesight NVR MS-Nxxxx-xxH
- Milesight NVR MS-Nxxxx-xxC
Weakness type
Related vulnerabilities
- CVE-2023-7028 — Weak Password Recovery Mechanism for Forgotten Password in GitLab
- CVE-2025-6216 — Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability
- CVE-2025-47646 — WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
- CVE-2026-18963 — Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
- CVE-2024-8878 — Unauthenticated Password Reset
- CVE-2022-3485 — Weak Password Recovery in ifm moneo appliance
- CVE-2024-11350 — AdForest <= 5.1.6 - Privilege Escalation via Password Reset/Account Takeover
- CVE-2022-50910 — Beehive Forum - Account Takeover