vendor:
TVIP 20000-21150
by:
d1g@segfault.net for NetworkSEC [NWSSA-001-2023]
7.2
CVSS
HIGH
LFI, RCE and SSH Root Access
78
CWE
Product Name: TVIP 20000-21150
Affected Version From: TVIP 20000-21150
Affected Version To: TVIP 20000-21150
Patch Exists: YES
Related CWE: CVE-2023-26609
CPE: h:abus:tvip_20000-21150
Platforms Tested: GM ARM Linux 2.6, Server: Boa/0.94.14rc21
2023
ABUS Security Camera TVIP 20000-21150 – LFI, RCE and SSH Root Access
During a recent engagement, a network camera was discovered. Web fuzzing revealed a URL of /device containing output about running processes as well as a pretty complete listing of webcontent which inevitably arose our suspicion. More research revealed that files w/ known LFI and RCE issues were present, leading to either arbitrary file reads or remote code execution, both w/ root privileges and using known default credentials (either admin:admin or manufacture:erutcafunam). After closer filesystem inspection, RCE led to a remote root SSH shell.
Mitigation:
Enforce strong authentication and authorization policies, and ensure that all users have unique credentials. Implement a secure configuration management process to ensure that all systems are configured securely and that all security patches are applied in a timely manner.