BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows attackers to access sensitive information such as configurations and recordings.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://github.com/eyJhb/blackvue-cve-2022 | third party advisory exploit |
https://shop.blackvue.com/product/dr750-2ch-ir-lte/ | product |
https://blackvue.com | product |
https://github.com/eyJhb/blackvue-cve-2023 | third party advisory exploit |