Argus Surveillance DVR 4.0.0.0 devices allow unauthenticated local file inclusion, leading to file disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.
View the template here CVE-2018-15745.yaml
References:
https://github.com/ARPSyndicate/cvemon