Advisories

COMMAX CVD-Axx DVR Weak Default Credentials Stream Disclosure

Go Back
severity
high
date
Affecting
  • CVD-AH04 DVR 4.4.1

  • CVD-AF04 DVR 4.4.1

  • CVD-AH16 DVR 5.1.4

  • CVD-AF16 DVR 4.4.1

  • CVD-AF08 DVR 5.1.2

  • CVD-AH08 DVR 5.1.2

CWE
  • CWE-1392 Use of Default Credentials
CVSS
8.5
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
LiquidWorm as Gjoko Krstic of Zero Science Lab
Description
COMMAX CVD-Axx DVR 5.1.4 contains weak default administrative credentials that allow remote password attacks and disclose RTSP stream. Attackers can exploit this by sending a POST request with the 'passkey' parameter set to '1234', allowing them to access the web control panel.