cvedb.io
CVE-2016-6537
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2016-09-19T01:59:09.383 · Last modified 2026-06-17T00:51:20.567

Summary

AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentials in HTTP Cookie headers, which allows context-dependent attacks to obtain sensitive information by reading these strings.

Affected products

aver — eh6108h\+_firmware

Does this affect you?

Add your gear to cvedb and we'll alert you only when aver ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.