KONGTOP DVR devices A303, A403, D303, D305, and D403 contain a backdoor that prints the login password via a Print_Password function call in certain circumstances.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/hucmosin/MyBook/blob/master/fu/DVR.pdf | third party advisory |
https://github.com/hucmosin/MyBook/blob/master/KONGTOP_DVR_devices_vulnerability_report-CVE-2018-10734.pdf | third party advisory |
https://github.com/hucmosin/Python_Small_Tool/blob/master/other/DVR_POC.py | third party advisory exploit |