vendor:
CVD-Axx DVR
by:
LiquidWorm
7,5
CVSS
HIGH
Weak Default Credentials Stream Disclosure
798
CWE
Product Name: CVD-Axx DVR
Affected Version From: CVD-AH04 DVR 4.4.1
Affected Version To: CVD-AH08 DVR 5.1.2
Patch Exists: NO
Related CWE: N/A
CPE: h:commax:cvd-ah04_dvr:4.4.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Boa/0.94.14rc19
2021
COMMAX CVD-Axx DVR 5.1.4 – Weak Default Credentials Stream Disclosure
COMMAX offers a wide range of proven AHD CCTV systems to meet customer needs and convenience in single or multi-family homes. The web control panel uses weak set of default administrative credentials that can be easily guessed in remote password attacks and disclose RTSP stream.
Mitigation:
Enforce strong passwords and two-factor authentication for all accounts.