PT-2020-12734 · Avertx · Avertx Auto Focus Night Vision Hd Indoor/Outdoor Ip Dome Camera Hd838+1
Published
2020-07-23
·
Updated
2020-07-29
·
CVE-2020-11624
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 (affected versions not specified)
AvertX Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438 (affected versions not specified)
Description
The issue concerns the lack of enforcement for changing the default password for the admin account. Although a pop-up window suggests changing the password, an administrator can click Cancel and proceed without making any changes. Furthermore, the default username is disclosed within the
login.js script. This makes the devices an easy target for malicious actors, as many IoT device attacks rely on default credentials.Recommendations
For AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838, consider changing the default admin password immediately to prevent unauthorized access.
For AvertX Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438, change the default admin password as soon as possible to minimize the risk of exploitation.
As a temporary workaround, restrict access to the
login.js script to prevent disclosure of the default username until a more permanent solution is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avertx Auto Focus Night Vision Hd Indoor/Outdoor Ip Dome Camera Hd838
Avertx Night Vision Hd Indoor/Outdoor Mini Ip Bullet Camera Hd438