vendor:
Smart Camera
by:
Pentest Partners
7,5
CVSS
HIGH
Command Injection
78
CWE
Product Name: Smart Camera
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Samsung Smart Camera Exploit
This exploit is used to change the web and root passwords of Samsung Smart Camera using the unauthenticated vulnerability found by zenofex. The exploit uses command injection to run a command on the device and convert a normal command into one using bash brace expansion. It then uses HTTP digest auth for urllib2 and uses sed to search and replace the old for new hash in the passwd.
Mitigation:
Ensure that the web and root passwords are changed regularly and that the device is kept up to date with the latest security patches.