Ring (formerly DoorBot) video doorbells allow remote attackers to obtain sensitive information about the wireless network configuration by pressing the set up button and leveraging an API in the GainSpan Wi-Fi module.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://fortiguard.com/zeroday/FG-VD-15-021 | third party advisory |
https://www.pentestpartners.com/security-blog/steal-your-wi-fi-key-from-your-doorbell-iot-wtf/ | third party advisory |
https://blog.fortinet.com/2016/01/22/cve-2015-4400-backdoorbot-network-configuration-leak-on-a-connected-doorbell | broken link |