vendor:
IP Camera
by:
icekam,xiao13,Rainbow,tfsec
7,5
CVSS
HIGH
Unauthorized Access
287
CWE
Product Name: IP Camera
Affected Version From: Compro IP70 2.08_7130218
Affected Version To: IP60, TN540
Patch Exists: YES
Related CWE: CVE-2021-40382
CPE: h:compro_technology:ip_camera
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=40382, https://www.infosecmatter.com/nessus-plugin-library/?id=62383, https://www.infosecmatter.com/nessus-plugin-library/?id=35188, https://www.infosecmatter.com/nessus-plugin-library/?id=34380, https://www.infosecmatter.com/nessus-plugin-library/?id=41221, https://www.infosecmatter.com/nessus-plugin-library/?id=137354, https://www.infosecmatter.com/nessus-plugin-library/?id=35347, https://www.infosecmatter.com/nessus-plugin-library/?id=33865, https://www.infosecmatter.com/nessus-plugin-library/?id=37068, https://www.infosecmatter.com/nessus-plugin-library/?id=72834
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2021
Compro Technology IP Camera – ‘ mjpegStreamer.cgi’ Screenshot Disclosure
There is an unauthorized access vulnerability, which can lead to unauthorized access to camera video screenshots. Payload: /mjpegStreamer.cgi
Mitigation:
Ensure that access to the camera is restricted to authorized users only and that all users have strong passwords.