Botnet Recall of Things

After a tough summer of botnet attacks by Internet-of-Things things came to a head last week and took down many popular websites for folks in the eastern US, more attention has finally been paid to what to do about this mess. We’ve wracked our brains, and the best we can come up with is that it’s the manufacturers’ responsibility to secure their devices.

Chinese DVR manufacturer Xiongmai, predictably, thinks that the end-user is to blame, but is also consenting to a recall of up to 300 million of their pre-2015 vintage cameras — the ones with hard-coded factory default passwords. …read more

Continue reading Botnet Recall of Things

VU#667480: AVer Information EH6108H+ hybrid DVR contains multiple vulnerabilities

AVer Information EH6108H+hybrid DVR,version X9.03.24.00.07l and possibly earlier,reportedly contains multiple vulnerabilities,including undocumented privileged accounts,authentication bypass,and information exposure. Continue reading VU#667480: AVer Information EH6108H+ hybrid DVR contains multiple vulnerabilities

RCE flaw affects DVRs sold by over 70 different vendors

RSA security researcher Rotem Kerner has discovered a remote code execution vulnerability that affects digital video recorders (DVRs) sold by more than 70 different vendors around the world. What are DVRs? Camera-based surveillance systems have become the norm in both public and private spaces, companies and retailers. Whether they are CCTV cameras or IP cameras, their operators often set them up to record what they capture for future perusal. In the case of CCTV systems, … More Continue reading RCE flaw affects DVRs sold by over 70 different vendors

VU#923388: Swann SRNVW-470 allows unauthorized access to video stream and contains a hard-coded password

Swann network video recorder(NVR)devices contain a hard-coded password and do not require authentication to view the video feed when accessing from specific URLs. Continue reading VU#923388: Swann SRNVW-470 allows unauthorized access to video stream and contains a hard-coded password