PT-2015-3333 · Lens · Lens Peek-A-View

Published

2015-07-04

·

Updated

2017-04-13

·

CVE-2015-2885

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Lens Peek-a-View (affected versions not specified)
Description The issue concerns the presence of predefined user accounts in the Lens Peek-a-View wireless video camera. Specifically, there are backdoor accounts with hardcoded passwords: admin with password 2601hx, user with password user, and guest with password guest. These accounts can be accessed through UART for the admin account and through the web interface for the user and guest accounts. Exploitation of this issue could allow a remote attacker to gain access to the device.
Recommendations For all affected versions, consider changing the default passwords of the backdoor accounts admin, user, and guest to strong, unique passwords to prevent unauthorized access. As a temporary workaround, consider disabling remote access to the device until secure passwords are set for these accounts. Restrict access to the UART interface and the web interface to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02467
CVE-2015-2885

Affected Products

Lens Peek-A-View