PT-2020-12734 · Avertx · Avertx Auto Focus Night Vision Hd Indoor/Outdoor Ip Dome Camera Hd838+1

Published

2020-07-23

·

Updated

2020-07-29

·

CVE-2020-11624

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838 (affected versions not specified) AvertX Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438 (affected versions not specified)
Description The issue concerns the lack of enforcement for changing the default password for the admin account. Although a pop-up window suggests changing the password, an administrator can click Cancel and proceed without making any changes. Furthermore, the default username is disclosed within the login.js script. This makes the devices an easy target for malicious actors, as many IoT device attacks rely on default credentials.
Recommendations For AvertX Auto focus Night Vision HD Indoor/Outdoor IP Dome Camera HD838, consider changing the default admin password immediately to prevent unauthorized access. For AvertX Night Vision HD Indoor/Outdoor Mini IP Bullet Camera HD438, change the default admin password as soon as possible to minimize the risk of exploitation. As a temporary workaround, restrict access to the login.js script to prevent disclosure of the default username until a more permanent solution is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11624

Affected Products

Avertx Auto Focus Night Vision Hd Indoor/Outdoor Ip Dome Camera Hd838
Avertx Night Vision Hd Indoor/Outdoor Mini Ip Bullet Camera Hd438