vendor:
IZON
by:
Mark Stanislav
9.8
CVSS
CRITICAL
Hard-coded Credentials
798
CWE
Product Name: IZON
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2013-6236
CPE:
Platforms Tested: iOS Mobile Application, Camera Firmware
2013
Stem Innovation ‘IZON’ Hard-coded Credentials (CVE-2013-6236)
Stem Innovation's IP camera called ‘IZON’ utilizes numerous hard-coded credentials within its Linux distribution and also the hidden web application running on the camera. These sets of credentials are never exposed to the end-user and cannot be changed through any normal operation of the camera. Further, using the web interface credentials will provide access to a camera stream and configuration details, including third-party API keys.
Mitigation:
Update to the latest firmware and hope for the best.