Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell via the UART Debugging Port.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://gncchome.com/collections/indoor-camera/products/c2-indoor-security-camera-1080p | product |
https://www.nsideattacklogic.de/advisories/NSIDE-SA-2024-001 | third party advisory exploit |