ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all devices. A remote attacker can take complete control of a device using default admin credentials.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://twitter.com/hack3rsca/status/839599437907386368 | press/media coverage |
http://www.securityfocus.com/bid/96720/info | third party advisory vdb entry |
https://twitter.com/Hfuhs/status/839252357221330944 | press/media coverage |
https://www.kb.cert.org/vuls/id/355151 | third party advisory us government resource |