vendor:
Smart Camera
by:
Alex Akinbi
8.8
CVSS
HIGH
Hardware- Multiple Vulnerabilities
287, 798, 259
CWE
Product Name: Smart Camera
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2019
Clever Dog Smart Camera
An attacker on the local network has unauthenticated access to the internal SD card via HTTP service on port 8000. The HTTP web server on the camera allows an attacker to download video archive recorded and saved on the external memory card attached. An attacker on the network can login remotely to the camera and gain root access. The device ships with hard-coded credentials, accessible from a telnet login prompt using credentials username: 'root' and password: '12345678'. Using a packet sniffer, an attacker on the same network can capture data packets and view captured user login password MD5 hash. A weak password can be cracked and used to login to the user account.
Mitigation:
Contact the vendor for further information regarding the proper mitigation of this vulnerability.