An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Authentication to the device is based on a username and password. The root credentials are the same across all devices of this model.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://www.eurofins-cybersecurity.com/news/connected-devices-baby-monitor/ | third party advisory exploit |
http://seclists.org/fulldisclosure/2024/Jul/14 | mailing list |