vendor:
I6032B-P POE 2.0MP Outdoor Camera
by:
Todor Donev
7.5
CVSS
HIGH
Remote Configuration Disclosure
N/A
CWE
Product Name: I6032B-P POE 2.0MP Outdoor Camera
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
I6032B-P POE 2.0MP Outdoor Camera – Remote Configuration Disclosure
This exploit allows an attacker to remotely access the configuration of a Revotech I6032B-P POE 1920x1080P 2.0MP Outdoor Camera. The exploit uses a GET request to the camera's CGI-bin/config.bin file, which returns a gzip-compressed file containing the camera's configuration.
Mitigation:
Ensure that the camera's configuration is not accessible from the internet and that access is restricted to trusted users.