Kguard Digital Video Recorder 104, 108, v2 does not have any authorization or authentication between an ActiveX client and the application server.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/132437/Kguard-Digital-Video-Recorder-Bypass-Issues.html | exploit vdb entry third party advisory |
http://www.securityfocus.com/archive/1/535822/100/0/threaded | mailing list |
https://www.academia.edu/11677554/Kguard_Digital_Video_Recorders_Multiple_Vulnerabilities | exploit third party advisory technical description |
http://www.securityfocus.com/bid/73032 | vdb entry third party advisory |