CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required.
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://www.cacagoo.com | product |
https://insights.oem.avira.com/serious-security-flaws-uncovered-in-cacagoo-ip-cameras/ | third party advisory exploit |