Vulnerability record · CVE-2022-29775 · published 21 June 2022
CVE-2022-29775: iSpy authentication bypass via crafted URL
Ispyconnect · Ispy
iSpyConnect iSpy v7.2.2.0 contains an improper authentication flaw (CWE-287) that lets attackers bypass authentication using a crafted URL. Because iSpy is a video surveillance application, an unauthenticated bypass exposes camera feeds and management functions. The record does not describe the exact URL pattern or which endpoints are affected.
Description
iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no privileges or user interaction, and high EPSS make this an urgent authentication bypass for any internet-exposed iSpy instance.
What it is
iSpyConnect iSpy v7.2.2.0 contains an improper authentication flaw (CWE-287) that lets attackers bypass authentication using a crafted URL. Because iSpy is a video surveillance application, an unauthenticated bypass exposes camera feeds and management functions. The record does not describe the exact URL pattern or which endpoints are affected.
Impact
An attacker gains unauthenticated access to the application, potentially viewing camera streams and reaching functionality intended only for authenticated users. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reachable over the network via a crafted URL with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not specify which URL or endpoint is abused.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.60272, 99th percentile), and references are only third-party advisories and write-ups, so no confirmed in-the-wild exploitation is stated.
What to do
- Upgrade iSpy to a version later than v7.2.2.0 if the vendor provides a fix; the record does not name a fixed version.
- Do not expose iSpy directly to the internet; place it behind a VPN or authenticated reverse proxy.
- Restrict network access to the iSpy web interface to trusted hosts and management networks.
- Review iSpy authentication and URL routing configuration for bypass patterns and apply vendor guidance.
- Monitor vendor and advisory channels for a patch or updated affected-version information.
Detection
- Inspect web server and iSpy logs for requests to unusual or malformed URLs that return success without a prior login.
- Alert on access to camera or management endpoints from sessions lacking an authenticated session identifier.
- Baseline normal URL paths and flag deviations, especially direct object or path manipulation attempts.
- Correlate unauthenticated requests with subsequent stream access or configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gist.github.com/securylight/79f673aa3a453c80c0e78f356a8f650b | Third Party Advisory |
| https://github.com/securylight/CVES_write_ups | Third Party Advisory |
| https://gist.github.com/securylight/79f673aa3a453c80c0e78f356a8f650b | Third Party Advisory |
| https://github.com/securylight/CVES_write_ups | Third Party Advisory |
Track CVE-2022-29775 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-29775), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.