vendor:
HiSilicon video encoders
by:
Alexei Kojenov
9.8
CVSS
CRITICAL
Backdoor Password
287
CWE
Product Name: HiSilicon video encoders
Affected Version From: Vendor-specific
Affected Version To: Vendor-specific
Patch Exists: YES
Related CWE: CVE-2020-24215
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
HiSilicon video encoders – full admin access via backdoor password
A vulnerability in HiSilicon video encoders from URayTech, J-Tech Digital, and ProVideoInstruments allows an attacker to gain full administrative access to the device by using a backdoor password. The backdoor password can be retrieved by sending a request to the device's web server. Once the password is retrieved, the attacker can log into the admin interface with the user 'admin' and the retrieved password.
Mitigation:
Users should update their devices to the latest version of the firmware to ensure that the backdoor password is removed.