The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant administrator’s credential and further control the devices.
Solution:
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://www.meritlilin.com/assets/uploads/support/file/M00166-TW.pdf | vendor advisory |
https://gist.github.com/keniver/86ebef688fb274b534da51ef1a84dd3e | third party advisory |
https://www.chtsecurity.com/news/0b733a38-e616-4ff3-86a6-13e710643388 | third party advisory |
https://www.twcert.org.tw/tw/cp-132-4678-aad70-1.html | third party advisory |